Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-27534
HistoryMar 20, 2023 - 12:00 a.m.

CVE-2023-27534

2023-03-2000:00:00
ubuntu.com
ubuntu.com
8
cve-2023-27534
path traversal
curl
sftp
code execution
unix
server access

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

51.8%

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation
causes the tilde (~) character to be wrongly replaced when used as a prefix
in the first path element, in addition to its intended use as the first
element to indicate a path relative to the user’s home directory. Attackers
can exploit this flaw to bypass filtering or execute arbitrary code by
crafting a path like /~2/foo while accessing a server with a specific user.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchcurl< 7.58.0-2ubuntu3.24UNKNOWN
ubuntu20.04noarchcurl< 7.68.0-1ubuntu2.18UNKNOWN
ubuntu22.04noarchcurl< 7.81.0-1ubuntu1.10UNKNOWN
ubuntu22.10noarchcurl< 7.85.0-1ubuntu0.5UNKNOWN
ubuntu23.04noarchcurl< 7.88.1-6ubuntu2UNKNOWN

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

51.8%