CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
Percentile
53.6%
Medium
Canonical Ubuntu
Harry Sintonen discovered that curl incorrectly handled HSTS support when multiple URLs are requested serially. A remote attacker could possibly use this issue to cause curl to use unencrypted connections. This issue only affected Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2023-23914) Harry Sintonen discovered that curl incorrectly handled HSTS support when multiple URLs are requested in parallel. A remote attacker could possibly use this issue to cause curl to use unencrypted connections. This issue only affected Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2023-23915) Patrick Monnerat discovered that curl incorrectly handled memory when processing requests with multi-header compression. A remote attacker could possibly use this issue to cause curl to consume resources, leading to a denial of service. (CVE-2023-23916) Update Instructions: Run sudo pro fix USN-5891-1
to fix the vulnerability. The problem can be corrected by updating your system to the following package versions: libcurl4-gnutls-dev – 7.81.0-1ubuntu1.8 libcurl4-openssl-dev – 7.81.0-1ubuntu1.8 libcurl3-gnutls – 7.81.0-1ubuntu1.8 libcurl4-doc – 7.81.0-1ubuntu1.8 libcurl3-nss – 7.81.0-1ubuntu1.8 libcurl4-nss-dev – 7.81.0-1ubuntu1.8 libcurl4 – 7.81.0-1ubuntu1.8 curl – 7.81.0-1ubuntu1.8 No subscription required
CVEs contained in this USN include: CVE-2023-23914, CVE-2023-23915, CVE-2023-23916.
Severity is medium unless otherwise noted.
Users of affected products are strongly encouraged to follow the mitigations below.
The Cloud Foundry project recommends upgrading the following releases:
2023-04-20: Initial vulnerability report published.
Vendor | Product | Version | CPE |
---|---|---|---|
cloudfoundry | bionic_stemcells | * | cpe:2.3:a:cloudfoundry:bionic_stemcells:*:*:*:*:*:*:*:* |
cloudfoundry | cflinuxfs3 | * | cpe:2.3:a:cloudfoundry:cflinuxfs3:*:*:*:*:*:*:*:* |
cloudfoundry | cflinuxfs4 | * | cpe:2.3:a:cloudfoundry:cflinuxfs4:*:*:*:*:*:*:*:* |
cloudfoundry | jammy_stemcells | * | cpe:2.3:a:cloudfoundry:jammy_stemcells:*:*:*:*:*:*:*:* |
cloudfoundry | cf-deployment | * | cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:* |
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
Percentile
53.6%