Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-38039

Опубликовано: 15 сент. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

released

8.2.1-1ubuntu3
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present
lunar

released

7.88.1-8ubuntu2.2
mantic

released

8.2.1-1ubuntu3

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 2 года назад

When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

CVSS3: 7.5
nvd
почти 2 года назад

When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

msrc
почти 2 года назад

Hackerone: CVE-2023-38039 HTTP headers eat all memory

CVSS3: 7.5
debian
почти 2 года назад

When curl retrieves an HTTP response, it stores the incoming headers s ...

suse-cvrf
почти 2 года назад

Security update for curl

7.5 High

CVSS3