Логотип exploitDog
bind: "CVE-2023-28320"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2023-28320"

Количество 15

Количество 15

ubuntu логотип

CVE-2023-28320

около 2 лет назад

A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2023-28320

около 2 лет назад

A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2023-28320

около 2 лет назад

A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2023-28320

около 2 лет назад

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2023-28320

около 2 лет назад

A denial of service vulnerability exists in curl <v8.1.0 in the way li ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-c8wj-435x-f2cc

около 2 лет назад

A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave.

CVSS3: 5.9
EPSS: Низкий
fstec логотип

BDU:2023-03612

около 2 лет назад

Уязвимость функций alarm() и siglongjmp() утилиты командной строки cURL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2230-1

около 2 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2227-1

около 2 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2224-2

почти 2 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2224-1

около 2 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2225-1

около 2 лет назад

Security update for curl

EPSS: Низкий
redos логотип

ROS-20230621-04

около 2 лет назад

Множественные уязвимости Curl

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2228-1

около 2 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2226-1

около 2 лет назад

Security update for curl

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-28320

A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave.

CVSS3: 5.9
1%
Низкий
около 2 лет назад
redhat логотип
CVE-2023-28320

A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave.

CVSS3: 3.7
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-28320

A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave.

CVSS3: 5.9
1%
Низкий
около 2 лет назад
msrc логотип
CVSS3: 5.9
1%
Низкий
около 2 лет назад
debian логотип
CVE-2023-28320

A denial of service vulnerability exists in curl <v8.1.0 in the way li ...

CVSS3: 5.9
1%
Низкий
около 2 лет назад
github логотип
GHSA-c8wj-435x-f2cc

A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave.

CVSS3: 5.9
1%
Низкий
около 2 лет назад
fstec логотип
BDU:2023-03612

Уязвимость функций alarm() и siglongjmp() утилиты командной строки cURL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
1%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2230-1

Security update for curl

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2227-1

Security update for curl

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2224-2

Security update for curl

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2023:2224-1

Security update for curl

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2225-1

Security update for curl

около 2 лет назад
redos логотип
ROS-20230621-04

Множественные уязвимости Curl

CVSS3: 7.5
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2228-1

Security update for curl

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2226-1

Security update for curl

около 2 лет назад

Уязвимостей на страницу