Lucene search

K
ubuntuUbuntuUSN-6718-3
HistoryApr 29, 2024 - 12:00 a.m.

curl vulnerabilities

2024-04-2900:00:00
ubuntu.com
13
ubuntu 24.04 lts
curl
http/https/ftp
cve-2024-2004
cve-2024-2398
denial of service

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

7.3 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.5%

Releases

  • Ubuntu 24.04 LTS

Packages

  • curl - HTTP, HTTPS, and FTP client and client libraries

Details

USN-6718-1 fixed vulnerabilities in curl. This update provides the
corresponding updates for Ubuntu 24.04 LTS.

Original advisory details:

Dan Fandrich discovered that curl would incorrectly use the default set of
protocols when a parameter option disabled all protocols without adding
any, contrary to expectations. This issue only affected Ubuntu 23.10.
(CVE-2024-2004)

It was discovered that curl incorrectly handled memory when limiting the
amount of headers when HTTP/2 server push is allowed. A remote attacker
could possibly use this issue to cause curl to consume resources, leading
to a denial of service. (CVE-2024-2398)

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

7.3 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.5%