USN-6237-3: curl vulnerabilities

Publication date

11 September 2023

Overview

Several security issues were fixed in curl.


Packages

  • curl - HTTP, HTTPS, and FTP client and client libraries

Details

USN-6237-1 fixed several vulnerabilities in curl. This update provides the
corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and
Ubuntu 18.04 LTS.

Original advisory details:

Hiroki Kurosawa discovered that curl incorrectly handled validating certain
certificate wildcards. A remote attacker could possibly use this issue to
spoof certain website certificates using IDN hosts. (CVE-2023-28321)

Hiroki Kurosawa discovered that curl incorrectly handled callbacks when
certain options are set by applications. This could cause applications
using curl to misbehave, resulting in information disclosure, or a denial
of service. (CVE-2023-28322)

It was discovered that curl incorrectly handled saving cookies to files. A
local attacker could possibly use this issue to create or overwrite files.
This issue only affected Ubuntu 22.10, and...

USN-6237-1 fixed several vulnerabilities in curl. This update provides the
corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and
Ubuntu 18.04 LTS.

Original advisory details:

Hiroki Kurosawa discovered that curl incorrectly handled validating certain
certificate wildcards. A remote attacker could possibly use this issue to
spoof certain website certificates using IDN hosts. (CVE-2023-28321)

Hiroki Kurosawa discovered that curl incorrectly handled callbacks when
certain options are set by applications. This could cause applications
using curl to misbehave, resulting in information disclosure, or a denial
of service. (CVE-2023-28322)

It was discovered that curl incorrectly handled saving cookies to files. A
local attacker could possibly use this issue to create or overwrite files.
This issue only affected Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-32001)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
18.04 bionic curl –  7.58.0-2ubuntu3.24+esm1  
libcurl3-gnutls –  7.58.0-2ubuntu3.24+esm1  
libcurl3-nss –  7.58.0-2ubuntu3.24+esm1  
libcurl4 –  7.58.0-2ubuntu3.24+esm1  
16.04 xenial curl –  7.47.0-1ubuntu2.19+esm9  
libcurl3 –  7.47.0-1ubuntu2.19+esm9  
libcurl3-gnutls –  7.47.0-1ubuntu2.19+esm9  
libcurl3-nss –  7.47.0-1ubuntu2.19+esm9  
14.04 trusty curl –  7.35.0-1ubuntu2.20+esm16  
libcurl3 –  7.35.0-1ubuntu2.20+esm16  
libcurl3-gnutls –  7.35.0-1ubuntu2.20+esm16  
libcurl3-nss –  7.35.0-1ubuntu2.20+esm16  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›