CVE-2023-27538
Summary
| CVE | CVE-2023-27538 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-30 20:15:00 UTC |
| Updated | 2024-03-27 14:46:00 UTC |
| Description | An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| curl: Multiple Vulnerabilities (GLSA 202310-12) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] [DLA 3398-1] curl security update |
MLIST |
lists.debian.org |
|
| curl - SSH connection too eager reuse still - CVE-2023-27538 |
CONFIRM |
curl.se |
|
| HackerOne |
MISC |
hackerone.com |
|
| March 2023 cURL/libcURL Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] Fedora 36 Update: curl-7.82.0-14.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161067 Oracle Enterprise Linux Security Update for curl (ELSA-2023-6679)
- 181748 Debian Security Update for curl (DLA 3398-1)
- 184522 Debian Security Update for curl (CVE-2023-27538)
- 199246 Ubuntu Security Notification for curl Vulnerabilities (USN-5964-1)
- 242295 Red Hat Update for curl (RHSA-2023:6679)
- 283820 Fedora Security Update for curl (FEDORA-2023-2884ba1528)
- 283865 Fedora Security Update for curl (FEDORA-2023-7e7414e64d)
- 284222 Fedora Security Update for curl (FEDORA-2023-0de03a9232)
- 330140 IBM AIX Multiple Vulnerabilities due to curl (curl_advisory2)
- 355390 Amazon Linux Security Advisory for curl : ALAS2-2023-2070
- 355415 Amazon Linux Security Advisory for curl : ALAS2023-2023-193
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 502707 Alpine Linux Security Update for curl
- 502720 Alpine Linux Security Update for curl
- 503104 Alpine Linux Security Update for curl
- 505862 Alpine Linux Security Update for curl
- 672889 EulerOS Security Update for curl (EulerOS-SA-2023-1816)
- 672907 EulerOS Security Update for curl (EulerOS-SA-2023-1798)
- 673091 EulerOS Security Update for curl (EulerOS-SA-2023-2188)
- 673174 EulerOS Security Update for curl (EulerOS-SA-2023-2308)
- 673187 EulerOS Security Update for curl (EulerOS-SA-2023-2328)
- 673616 EulerOS Security Update for curl (EulerOS-SA-2023-2635)
- 673678 EulerOS Security Update for curl (EulerOS-SA-2023-2677)
- 691088 Free Berkeley Software Distribution (FreeBSD) Security Update for curl (0d7d104c-c6fb-11ed-8a4b-080027f5fec9)
- 710772 Gentoo Linux curl Multiple Vulnerabilities (GLSA 202310-12)
- 753819 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2023:0865-1)
- 753857 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2023:1711-1)
- 754020 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2023:2226-1)
- 754021 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2023:2228-1)
- 906768 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (25848-1)
- 907361 Common Base Linux Mariner (CBL-Mariner) Security Update for rust (25808-1)
- 907651 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (25803-1)
- 941357 AlmaLinux Security Update for curl (ALSA-2023:6679)