Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-46219

Опубликовано: 06 дек. 2023
Источник: redhat
CVSS3: 5.3

Описание

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

A security bypass flaw was found in Curl, which can be triggered by saving HSTS data to an excessively long file name. This issue occurs due to an error in handling HSTS long file names, leading to the removal of all contents from the file during the save process, and may allow a remote attacker to send a specially crafted request to use files without awareness of the HSTS status and enable a Man-in-the-Middle (MitM) attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlNot affected
Red Hat Enterprise Linux 8curlNot affected
Red Hat Enterprise Linux 9curlNot affected
Red Hat Satellite 6puppet-agentAffected
JBoss Core Services for RHEL 8jbcs-httpd24-curlFixedRHSA-2024:131618.03.2024
JBoss Core Services on RHEL 7jbcs-httpd24-curlFixedRHSA-2024:131618.03.2024
Text-Only JBCScurlFixedRHSA-2024:131718.03.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-311
https://bugzilla.redhat.com/show_bug.cgi?id=2252034curl: excessively long file name may lead to unknown HSTS status

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

CVSS3: 5.3
nvd
больше 1 года назад

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

CVSS3: 5.3
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 5.3
debian
больше 1 года назад

When saving HSTS data to an excessively long file name, curl could end ...

CVSS3: 5.3
redos
12 месяцев назад

Уязвимость curl

5.3 Medium

CVSS3

Уязвимость CVE-2023-46219