Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-46219

Опубликовано: 12 дек. 2023
Источник: debian
EPSS Низкий

Описание

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed8.5.0-1package
curlfixed7.88.1-10+deb12u5bookwormpackage
curlignoredbullseyepackage
curlnot-affectedbusterpackage

Примечания

  • Introduced by: https://github.com/curl/curl/commit/20f9dd6bae50b7223171b17ba7798946e74f877f (curl-7_84_0)

  • The issue is introduced with the fix for CVE-2022-32207.

  • Fixed by: https://github.com/curl/curl/commit/73b65e94f3531179de45c6f3c836a610e3d0a846 (curl-8_5_0)

  • https://curl.se/docs/CVE-2023-46219.html

EPSS

Процентиль: 22%
0.00072
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 2 года назад

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

CVSS3: 5.3
redhat
почти 2 года назад

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

CVSS3: 5.3
nvd
почти 2 года назад

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

CVSS3: 5.3
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 5.3
redos
больше 1 года назад

Уязвимость libcurl

EPSS

Процентиль: 22%
0.00072
Низкий