Lucene search

K
ubuntuUbuntuUSN-6718-2
HistoryMar 27, 2024 - 12:00 a.m.

curl vulnerability

2024-03-2700:00:00
ubuntu.com
15
ubuntu
curl
vulnerability
http/https/ftp
denial of service

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

7.4 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.5%

Releases

  • Ubuntu 18.04 ESM
  • Ubuntu 16.04 ESM

Packages

  • curl - HTTP, HTTPS, and FTP client and client libraries

Details

USN-6718-1 fixed a vulnerability in curl. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.

Original advisory details:

It was discovered that curl incorrectly handled memory when limiting the
amount of headers when HTTP/2 server push is allowed. A remote attacker
could possibly use this issue to cause curl to consume resources, leading
to a denial of service. (CVE-2024-2398)

OSVersionArchitecturePackageVersionFilename
Ubuntu18.04noarchcurl< 7.58.0-2ubuntu3.24+esm4UNKNOWN
Ubuntu18.04noarchcurl< 7.58.0-2ubuntu3.24UNKNOWN
Ubuntu18.04noarchcurl-dbgsym< 7.58.0-2ubuntu3.24UNKNOWN
Ubuntu18.04noarchlibcurl3-gnutls< 7.58.0-2ubuntu3.24UNKNOWN
Ubuntu18.04noarchlibcurl3-gnutls-dbgsym< 7.58.0-2ubuntu3.24UNKNOWN
Ubuntu18.04noarchlibcurl3-nss< 7.58.0-2ubuntu3.24UNKNOWN
Ubuntu18.04noarchlibcurl3-nss-dbgsym< 7.58.0-2ubuntu3.24UNKNOWN
Ubuntu18.04noarchlibcurl4< 7.58.0-2ubuntu3.24UNKNOWN
Ubuntu18.04noarchlibcurl4-dbgsym< 7.58.0-2ubuntu3.24UNKNOWN
Ubuntu18.04noarchlibcurl4-doc< 7.58.0-2ubuntu3.24UNKNOWN
Rows per page:
1-10 of 361

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

7.4 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.5%