跳转到帖子

SUSE: CVE-2023-23915: SUSE Linux Security Advisory

recommended_posts

发布于
  • Members

SUSE: CVE-2023-23915: SUSE Linux Security Advisory

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
Published
02/15/2023
Created
02/17/2023
Added
02/16/2023
Modified
01/28/2025

Description

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.

Solution(s)

  • suse-upgrade-curl
  • suse-upgrade-libcurl-devel
  • suse-upgrade-libcurl-devel-32bit
  • suse-upgrade-libcurl4
  • suse-upgrade-libcurl4-32bit

References

  • https://attackerkb.com/topics/cve-2023-23915
  • CVE - 2023-23915
  • 查看数 695
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…