Логотип exploitDog
bind:"CVE-2023-32001"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-32001"

Количество 8

Количество 8

ubuntu логотип

CVE-2023-32001

больше 2 лет назад

Rejected reason: We issued this CVE pre-maturely, as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.

EPSS: Низкий
redhat логотип

CVE-2023-32001

больше 2 лет назад

A flaw was found in the curl package. This race condition modifies the behavior of symbolic link files in affected components which might be followed instead of overwritten when the condition is met, leading to undesired and potentially destructive behavior.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-32001

больше 2 лет назад

Rejected reason: We issued this CVE pre-maturely, as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.

EPSS: Низкий
msrc логотип

CVE-2023-32001

больше 1 года назад

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2891-1

больше 2 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2880-1

больше 2 лет назад

Security update for curl

EPSS: Низкий
github логотип

GHSA-xc3w-ghxg-pw5f

больше 2 лет назад

libcurl can be told to save cookie, HSTS and/or alt-svc data to files. When doing this, it called `stat()` followed by `fopen()` in a way that made it vulnerable to a TOCTOU race condition problem. By exploiting this flaw, an attacker could trick the victim to create or overwrite protected files holding this data in ways it was not intended to.

EPSS: Низкий
fstec логотип

BDU:2023-04304

больше 2 лет назад

Уязвимость функции fopen() библиотеки libcurl, связанная с ошибками управления состоянием, позволяющая нарушителю создать или перезаписать защищенные файлы

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-32001

Rejected reason: We issued this CVE pre-maturely, as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.

больше 2 лет назад
redhat логотип
CVE-2023-32001

A flaw was found in the curl package. This race condition modifies the behavior of symbolic link files in affected components which might be followed instead of overwritten when the condition is met, leading to undesired and potentially destructive behavior.

CVSS3: 5.5
больше 2 лет назад
nvd логотип
CVE-2023-32001

Rejected reason: We issued this CVE pre-maturely, as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.

больше 2 лет назад
msrc логотип
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:2891-1

Security update for curl

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2880-1

Security update for curl

больше 2 лет назад
github логотип
GHSA-xc3w-ghxg-pw5f

libcurl can be told to save cookie, HSTS and/or alt-svc data to files. When doing this, it called `stat()` followed by `fopen()` in a way that made it vulnerable to a TOCTOU race condition problem. By exploiting this flaw, an attacker could trick the victim to create or overwrite protected files holding this data in ways it was not intended to.

больше 2 лет назад
fstec логотип
BDU:2023-04304

Уязвимость функции fopen() библиотеки libcurl, связанная с ошибками управления состоянием, позволяющая нарушителю создать или перезаписать защищенные файлы

CVSS3: 5.5
больше 2 лет назад

Уязвимостей на страницу