Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

ubuntu логотип

CVE-2023-32001

около 3 лет назад

Rejected reason: We issued this CVE pre-maturely, as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.

EPSS: Низкий
redhat логотип

CVE-2023-32001

около 3 лет назад

A flaw was found in the curl package. This race condition modifies the behavior of symbolic link files in affected components which might be followed instead of overwritten when the condition is met, leading to undesired and potentially destructive behavior.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-32001

около 3 лет назад

Rejected reason: We issued this CVE pre-maturely, as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.

EPSS: Низкий
msrc логотип

CVE-2023-32001

около 2 лет назад

Rejected reason: We issued this CVE pre-maturely as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2891-1

около 3 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2880-1

около 3 лет назад

Security update for curl

EPSS: Низкий
github логотип

GHSA-xc3w-ghxg-pw5f

около 3 лет назад

libcurl can be told to save cookie, HSTS and/or alt-svc data to files. When doing this, it called `stat()` followed by `fopen()` in a way that made it vulnerable to a TOCTOU race condition problem. By exploiting this flaw, an attacker could trick the victim to create or overwrite protected files holding this data in ways it was not intended to.

EPSS: Низкий
fstec логотип

BDU:2023-04304

около 3 лет назад

Уязвимость функции fopen() библиотеки libcurl, связанная с ошибками управления состоянием, позволяющая нарушителю создать или перезаписать защищенные файлы

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-32001

Rejected reason: We issued this CVE pre-maturely, as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.

около 3 лет назад
redhat логотип
CVE-2023-32001

A flaw was found in the curl package. This race condition modifies the behavior of symbolic link files in affected components which might be followed instead of overwritten when the condition is met, leading to undesired and potentially destructive behavior.

CVSS3: 5.5
около 3 лет назад
nvd логотип
CVE-2023-32001

Rejected reason: We issued this CVE pre-maturely, as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.

около 3 лет назад
msrc логотип
CVE-2023-32001

Rejected reason: We issued this CVE pre-maturely as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2891-1

Security update for curl

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2880-1

Security update for curl

около 3 лет назад
github логотип
GHSA-xc3w-ghxg-pw5f

libcurl can be told to save cookie, HSTS and/or alt-svc data to files. When doing this, it called `stat()` followed by `fopen()` in a way that made it vulnerable to a TOCTOU race condition problem. By exploiting this flaw, an attacker could trick the victim to create or overwrite protected files holding this data in ways it was not intended to.

около 3 лет назад
fstec логотип
BDU:2023-04304

Уязвимость функции fopen() библиотеки libcurl, связанная с ошибками управления состоянием, позволяющая нарушителю создать или перезаписать защищенные файлы

CVSS3: 5.5
около 3 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.