USN-6944-1: curl vulnerability
Published Aug 5, 2024
·Updated
Dov Murik discovered that curl incorrectly handled parsing ASN.1 Generalized Time fields. A remote attacker could use this issue to cause curl to crash, resulting in a denial of service, or possibly obtain sensitive memory contents.
Affected Software
22 affected componentsFixes available
All of the following
ubuntu/curl<8.5.0-2ubuntu10.2
8.5.0-2ubuntu10.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/libcurl3t64-gnutls<8.5.0-2ubuntu10.2
8.5.0-2ubuntu10.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/libcurl4t64<8.5.0-2ubuntu10.2
8.5.0-2ubuntu10.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/curl<7.81.0-1ubuntu1.17
7.81.0-1ubuntu1.17
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libcurl3-gnutls<7.81.0-1ubuntu1.17
7.81.0-1ubuntu1.17
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libcurl3-nss<7.81.0-1ubuntu1.17
7.81.0-1ubuntu1.17
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libcurl4<7.81.0-1ubuntu1.17
7.81.0-1ubuntu1.17
Ubuntu Ubuntu=22.04
All of the following
ubuntu/curl<7.68.0-1ubuntu2.23
7.68.0-1ubuntu2.23
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libcurl3-gnutls<7.68.0-1ubuntu2.23
7.68.0-1ubuntu2.23
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libcurl3-nss<7.68.0-1ubuntu2.23
7.68.0-1ubuntu2.23
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libcurl4<7.68.0-1ubuntu2.23
7.68.0-1ubuntu2.23
Ubuntu Ubuntu=20.04
Event History
Aug 5, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6944-1?
The severity of USN-6944-1 is high as it may lead to denial of service or potential leakage of sensitive memory data.
2
How do I fix USN-6944-1?
To fix USN-6944-1, update curl and its related packages to the latest versions as specified in the advisory.
3
What does USN-6944-1 affect?
USN-6944-1 affects multiple versions of curl and libcurl packages on Ubuntu 20.04, 22.04, and 24.04.
4
Who discovered the vulnerability in USN-6944-1?
The vulnerability in USN-6944-1 was discovered by researcher Dov Murik.
5
Can USN-6944-1 be exploited remotely?
Yes, USN-6944-1 can be exploited by remote attackers to cause curl to crash.