Логотип exploitDog
bind:CVE-2023-27538
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-27538

Количество 14

Количество 14

ubuntu логотип

CVE-2023-27538

около 2 лет назад

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2023-27538

около 2 лет назад

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-27538

около 2 лет назад

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-27538

около 2 лет назад

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2023-27538

около 2 лет назад

An authentication bypass vulnerability exists in libcurl prior to v8.0 ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-cgj3-cvg6-pcvh

около 2 лет назад

An authentication bypass vulnerability exists in libcurl v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2023-02103

около 2 лет назад

Уязвимость библиотеки libcurl, связанная с обходом процедуры аутентификации, позволяющая нарушителю повторно использовать неподходящее соединение

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20230407-01

около 2 лет назад

Множественные уязвимости libcurl

CVSS3: 5.9
EPSS: Низкий
oracle-oval логотип

ELSA-2023-6679

больше 1 года назад

ELSA-2023-6679: curl security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1582-1

около 2 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0865-1

около 2 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1711-1

около 2 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2228-1

около 2 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2226-1

около 2 лет назад

Security update for curl

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-27538

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
redhat логотип
CVE-2023-27538

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-27538

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-27538

An authentication bypass vulnerability exists in libcurl prior to v8.0 ...

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-cgj3-cvg6-pcvh

An authentication bypass vulnerability exists in libcurl v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2023-02103

Уязвимость библиотеки libcurl, связанная с обходом процедуры аутентификации, позволяющая нарушителю повторно использовать неподходящее соединение

CVSS3: 6.5
0%
Низкий
около 2 лет назад
redos логотип
ROS-20230407-01

Множественные уязвимости libcurl

CVSS3: 5.9
около 2 лет назад
oracle-oval логотип
ELSA-2023-6679

ELSA-2023-6679: curl security update (MODERATE)

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:1582-1

Security update for curl

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0865-1

Security update for curl

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:1711-1

Security update for curl

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2228-1

Security update for curl

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2226-1

Security update for curl

около 2 лет назад

Уязвимостей на страницу