Lucene search

K
almalinuxAlmaLinuxALSA-2023:6679
HistoryNov 07, 2023 - 12:00 a.m.

Moderate: curl security update

2023-11-0700:00:00
errata.almalinux.org
19
curl
security update
libcurl
http
ftp
ldap
gss delegation
telnet
sftp
ssh
cvss score
almalinux
unix

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

Low

EPSS

0.003

Percentile

71.7%

The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.

Security Fix(es):

  • curl: GSS delegation too eager connection re-use (CVE-2023-27536)
  • curl: TELNET option IAC injection (CVE-2023-27533)
  • curl: SFTP path ~ resolving discrepancy (CVE-2023-27534)
  • curl: SSH connection too eager reuse still (CVE-2023-27538)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

Low

EPSS

0.003

Percentile

71.7%