Lucene search

K
redhatRedHatRHSA-2023:6679
HistoryNov 07, 2023 - 6:11 a.m.

(RHSA-2023:6679) Moderate: curl security update

2023-11-0706:11:52
access.redhat.com
29
curl
security update
gss delegation
telnet injection
sftp path discrepancy
ssh connection
cve
red hat enterprise linux 9.3.

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7

Confidence

Low

EPSS

0.003

Percentile

71.7%

The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.

Security Fix(es):

  • curl: GSS delegation too eager connection re-use (CVE-2023-27536)

  • curl: TELNET option IAC injection (CVE-2023-27533)

  • curl: SFTP path ~ resolving discrepancy (CVE-2023-27534)

  • curl: SSH connection too eager reuse still (CVE-2023-27538)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.3 Release Notes linked from the References section.

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7

Confidence

Low

EPSS

0.003

Percentile

71.7%