Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-28319

Опубликовано: 26 мая 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting sensitive heap-based data into the error message that might be shown to users or otherwise get leaked and revealed.

РелизСтатусПримечание
bionic

not-affected

7.58.0-2ubuntu3.24
devel

not-affected

code not compiled
esm-infra-legacy/trusty

not-affected

esm-infra/bionic

not-affected

7.58.0-2ubuntu3.24
esm-infra/focal

not-affected

7.68.0-1ubuntu2.18
esm-infra/xenial

not-affected

focal

not-affected

7.68.0-1ubuntu2.18
jammy

not-affected

7.81.0-1ubuntu1.20
kinetic

not-affected

code not compiled
lunar

not-affected

code not compiled

Показывать по

EPSS

Процентиль: 54%
0.0032
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
около 2 лет назад

A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting sensitive heap-based data into the error message that might be shown to users or otherwise get leaked and revealed.

CVSS3: 7.5
nvd
около 2 лет назад

A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting sensitive heap-based data into the error message that might be shown to users or otherwise get leaked and revealed.

CVSS3: 7.5
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 7.5
debian
около 2 лет назад

A use after free vulnerability exists in curl <v8.1.0 in the way libcu ...

CVSS3: 7.5
github
около 2 лет назад

A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting sensitive heap-based data into the error message that might be shown to users or otherwise get leaked and revealed.

EPSS

Процентиль: 54%
0.0032
Низкий

7.5 High

CVSS3