Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-46219

Опубликовано: 12 дек. 2023
Источник: debian
EPSS Низкий

Описание

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed8.5.0-1package
curlfixed7.88.1-10+deb12u5bookwormpackage
curlignoredbullseyepackage
curlnot-affectedbusterpackage

Примечания

  • Introduced by: https://github.com/curl/curl/commit/20f9dd6bae50b7223171b17ba7798946e74f877f (curl-7_84_0)

  • The issue is introduced with the fix for CVE-2022-32207.

  • Fixed by: https://github.com/curl/curl/commit/73b65e94f3531179de45c6f3c836a610e3d0a846 (curl-8_5_0)

  • https://curl.se/docs/CVE-2023-46219.html

EPSS

Процентиль: 63%
0.01133
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 2 лет назад

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

CVSS3: 5.3
redhat
больше 2 лет назад

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

CVSS3: 5.3
nvd
больше 2 лет назад

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

CVSS3: 5.3
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 5.3
redos
около 2 лет назад

Уязвимость libcurl

EPSS

Процентиль: 63%
0.01133
Низкий