CVE-2023-23916
Summary
| CVE | CVE-2023-23916 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-23 20:15:00 UTC |
| Updated | 2024-03-27 14:54:00 UTC |
| Description | An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain" wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a "malloc bomb", making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160501 Oracle Enterprise Linux Security Update for curl (ELSA-2023-1140)
- 160545 Oracle Enterprise Linux Security Update for curl (ELSA-2023-1701)
- 181609 Debian Security Update for curl (DLA 3341-1)
- 181662 Debian Security Update for curl (DSA 5365-1)
- 184640 Debian Security Update for curl (CVE-2023-23916)
- 199191 Ubuntu Security Notification for curl Vulnerabilities (USN-5891-1)
- 241245 Red Hat Update for curl (RHSA-2023:1140)
- 241335 Red Hat Update for curl (RHSA-2023:1701)
- 241356 Red Hat Update for curl (RHSA-2023:1842)
- 241574 Red Hat Update for JBoss Core Services (RHSA-2023:3354)
- 241641 Red Hat Update for curl (RHSA-2023:3460)
- 241829 Red Hat Update for curl (RHSA-2023:4139)
- 283721 Fedora Security Update for curl (FEDORA-2023-ddf6575695)
- 283751 Fedora Security Update for curl (FEDORA-2023-94df30cbec)
- 330140 IBM AIX Multiple Vulnerabilities due to curl (curl_advisory2)
- 354789 Amazon Linux Security Advisory for curl : ALAS2-2023-1986
- 354899 Amazon Linux Security Advisory for curl : ALAS-2023-1729
- 355123 Amazon Linux Security Advisory for curl : ALAS2023-2023-114
- 378120 Alibaba Cloud Linux Security Update for curl (ALINUX3-SA-2023:0032)
- 378438 HCL BigFix Multiple Security Vulnerabilities (KB0103724)
- 378453 NetApp Clustered Data Open Network Technology for Appliance Products (ONTAP) Denial of Service (DoS) Vulnerability (NTAP-20230309-0006)
- 378560 IBM MQ LibcURL Multiple Vulnerabilities (6952185)
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 502664 Alpine Linux Security Update for curl
- 502667 Alpine Linux Security Update for curl
- 502668 Alpine Linux Security Update for curl
- 502719 Alpine Linux Security Update for curl
- 503103 Alpine Linux Security Update for curl
- 505861 Alpine Linux Security Update for curl
- 672874 EulerOS Security Update for curl (EulerOS-SA-2023-1590)
- 672973 EulerOS Security Update for curl (EulerOS-SA-2023-1838)
- 672997 EulerOS Security Update for curl (EulerOS-SA-2023-1862)
- 673128 EulerOS Security Update for curl (EulerOS-SA-2023-2286)
- 673152 EulerOS Security Update for curl (EulerOS-SA-2023-2262)
- 691083 Free Berkeley Software Distribution (FreeBSD) Security Update for curl (be233fc6-bae7-11ed-a4fb-080027f5fec9)
- 710772 Gentoo Linux curl Multiple Vulnerabilities (GLSA 202310-12)
- 753701 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2023:0425-1)
- 753702 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2023:0429-1)
- 753857 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2023:1711-1)
- 754020 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2023:2226-1)
- 754021 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2023:2228-1)
- 905583 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (13632)
- 905587 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (13628)
- 905588 Common Base Linux Mariner (CBL-Mariner) Security Update for rust (13636)
- 905589 Common Base Linux Mariner (CBL-Mariner) Security Update for cmake (13627)
- 905594 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (13657)
- 905595 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (13653)
- 905597 Common Base Linux Mariner (CBL-Mariner) Security Update for rust (13658)
- 905601 Common Base Linux Mariner (CBL-Mariner) Security Update for cmake (13651)
- 906619 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (13653-3)
- 906699 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (13628-1)
- 906873 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (13657-1)
- 907408 Common Base Linux Mariner (CBL-Mariner) Security Update for rust (13658-1)
- 940957 AlmaLinux Security Update for curl (ALSA-2023:1140)
- 940984 AlmaLinux Security Update for curl (ALSA-2023:1701)
- 960671 Rocky Linux Security Update for curl (RLSA-2023:1140)