发布于3月6日3月6日 Members FreeBSD: VID-A4F8BB03-F52F-11ED-9859-080027083A05 (CVE-2023-28320): curl -- multiple vulnerabilities Severity 7 CVSS (AV:N/AC:M/Au:N/C:N/I:N/A:C) Published 03/21/2023 Created 05/23/2023 Added 05/20/2023 Modified 01/28/2025 Description Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below. From VID-A4F8BB03-F52F-11ED-9859-080027083A05: Wei Chong Tan, Harry Sintonen, and Hiroki Kurosawa reports: This update fixes 4 security vulnerabilities: Medium CVE-2023-28319: UAF in SSH sha256 fingerprint check. Reported by Wei Chong Tan on 2023-03-21 Low CVE-2023-28320: siglongjmp race condition. Reported by Harry Sintonen on 2023-04-02 Low CVE-2023-28321: IDN wildcard match. Reported by Hiroki Kurosawa on 2023-04-17 Low CVE-2023-28322: more POST-after-PUT confusion. Reported by Hiroki Kurosawa on 2023-04-19 Solution(s) freebsd-upgrade-package-curl References CVE-2023-28320 SUSE-SU-2023:2224-1 SUSE-SU-2023:2225-1 SUSE-SU-2023:2226-1 SUSE-SU-2023:2227-1 SUSE-SU-2023:2228-1 SUSE-SU-2023:2230-1 View more