CVE-2023-28319
Summary
| CVE | CVE-2023-28319 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-26 21:15:00 UTC |
| Updated | 2023-10-20 18:42:00 UTC |
| Description | A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting sensitive heap-based data into the error message that might be shown to users or otherwise get leaked and revealed. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Full Disclosure: APPLE-SA-2023-07-24-5 macOS Monterey 12.6.8 |
FULLDISC |
seclists.org |
|
| About the security content of macOS Ventura 13.5 - Apple Support |
CONFIRM |
support.apple.com |
|
| About the security content of macOS Monterey 12.6.8 - Apple Support |
CONFIRM |
support.apple.com |
|
| curl: Multiple Vulnerabilities (GLSA 202310-12) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| About the security content of macOS Big Sur 11.7.9 - Apple Support |
CONFIRM |
support.apple.com |
|
| HackerOne |
MISC |
hackerone.com |
|
| Full Disclosure: APPLE-SA-2023-07-24-4 macOS Ventura 13.5 |
FULLDISC |
seclists.org |
|
| Full Disclosure: APPLE-SA-2023-07-24-6 macOS Big Sur 11.7.9 |
FULLDISC |
seclists.org |
|
| May 2023 cURL/libcURL Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 183843 Debian Security Update for curl (CVE-2023-28319)
- 241954 Red Hat Update for JBoss Core Services (RHSA-2023:4629)
- 355747 Amazon Linux Security Advisory for curl : ALAS2023-2023-270
- 378687 Apple macOS Ventura 13.5 Not Installed (HT213843)
- 378688 Apple macOS Monterey 12.6.8 Not Installed (HT213844)
- 378689 Apple macOS Big Sur 11.7.9 Not Installed (HT213845)
- 503014 Alpine Linux Security Update for curl
- 691172 Free Berkeley Software Distribution (FreeBSD) Security Update for curl (a4f8bb03-f52f-11ed-9859-080027083a05)
- 710772 Gentoo Linux curl Multiple Vulnerabilities (GLSA 202310-12)
- 754069 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2023:2225-1)
- 907198 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (26795-1)
- 907375 Common Base Linux Mariner (CBL-Mariner) Security Update for rust (26810-1)
- 907644 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (26807-1)