Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-4523

Опубликовано: 10 авг. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-4523: curl security update (MODERATE)

[7.61.1-30.el8_8.3]

  • GSS delegation too eager connection re-use (CVE-2023-27536)
  • fix host name wildcard checking (CVE-2023-28321)
  • rebuild certs with 2048-bit RSA keys

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

curl

7.61.1-30.el8_8.3

libcurl

7.61.1-30.el8_8.3

libcurl-devel

7.61.1-30.el8_8.3

libcurl-minimal

7.61.1-30.el8_8.3

Oracle Linux x86_64

curl

7.61.1-30.el8_8.3

libcurl

7.61.1-30.el8_8.3

libcurl-devel

7.61.1-30.el8_8.3

libcurl-minimal

7.61.1-30.el8_8.3

Связанные CVE

Связанные уязвимости

rocky
больше 1 года назад

Moderate: curl security update

suse-cvrf
около 2 лет назад

Security update for curl

suse-cvrf
около 2 лет назад

Security update for curl

CVSS3: 5.9
ubuntu
около 2 лет назад

An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.

CVSS3: 5.9
redhat
больше 2 лет назад

An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.