First published: Mon Sep 11 2023(Updated: )
USN-6237-1 fixed several vulnerabilities in curl. This update provides the corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. Original advisory details: Hiroki Kurosawa discovered that curl incorrectly handled validating certain certificate wildcards. A remote attacker could possibly use this issue to spoof certain website certificates using IDN hosts. (CVE-2023-28321) Hiroki Kurosawa discovered that curl incorrectly handled callbacks when certain options are set by applications. This could cause applications using curl to misbehave, resulting in information disclosure, or a denial of service. (CVE-2023-28322) It was discovered that curl incorrectly handled saving cookies to files. A local attacker could possibly use this issue to create or overwrite files. This issue only affected Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-32001)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/curl | <7.58.0-2ubuntu3.24+esm1 | 7.58.0-2ubuntu3.24+esm1 |
=18.04 | ||
All of | ||
ubuntu/libcurl3-gnutls | <7.58.0-2ubuntu3.24+esm1 | 7.58.0-2ubuntu3.24+esm1 |
=18.04 | ||
All of | ||
ubuntu/libcurl3-nss | <7.58.0-2ubuntu3.24+esm1 | 7.58.0-2ubuntu3.24+esm1 |
=18.04 | ||
All of | ||
ubuntu/libcurl4 | <7.58.0-2ubuntu3.24+esm1 | 7.58.0-2ubuntu3.24+esm1 |
=18.04 | ||
All of | ||
ubuntu/curl | <7.47.0-1ubuntu2.19+esm9 | 7.47.0-1ubuntu2.19+esm9 |
=16.04 | ||
All of | ||
ubuntu/libcurl3 | <7.47.0-1ubuntu2.19+esm9 | 7.47.0-1ubuntu2.19+esm9 |
=16.04 | ||
All of | ||
ubuntu/libcurl3-gnutls | <7.47.0-1ubuntu2.19+esm9 | 7.47.0-1ubuntu2.19+esm9 |
=16.04 | ||
All of | ||
ubuntu/libcurl3-nss | <7.47.0-1ubuntu2.19+esm9 | 7.47.0-1ubuntu2.19+esm9 |
=16.04 | ||
All of | ||
ubuntu/curl | <7.35.0-1ubuntu2.20+esm16 | 7.35.0-1ubuntu2.20+esm16 |
=14.04 | ||
All of | ||
ubuntu/libcurl3 | <7.35.0-1ubuntu2.20+esm16 | 7.35.0-1ubuntu2.20+esm16 |
=14.04 | ||
All of | ||
ubuntu/libcurl3-gnutls | <7.35.0-1ubuntu2.20+esm16 | 7.35.0-1ubuntu2.20+esm16 |
=14.04 | ||
All of | ||
ubuntu/libcurl3-nss | <7.35.0-1ubuntu2.20+esm16 | 7.35.0-1ubuntu2.20+esm16 |
=14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this advisory is USN-6237-3.
The affected software for this vulnerability is curl, libcurl3-gnutls, libcurl3-nss, and libcurl4.
The severity of this vulnerability is not mentioned in the advisory.
To fix this vulnerability, you need to update curl and its related packages to the specified versions.
You can find more information about this vulnerability in the references section of the advisory.