Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2023-32001

Published: 19 July 2023

We issued this CVE pre-maturely, as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.

Notes

AuthorNote
mdeslaur
introduced in 7.84.0 by
https://github.com/curl/curl/commit/20f9dd6bae50b722

Priority

Medium

Cvss 3 Severity Score

5.0

Score breakdown

Status

Package Release Status
curl
Launchpad, Ubuntu, Debian
trusty Not vulnerable
(code not present)
xenial Not vulnerable
(code not present)
bionic Not vulnerable
(co1de not present)
focal Not vulnerable
(code not present)
jammy Not vulnerable
(code not present)
kinetic
Released (7.85.0-1ubuntu0.6)
lunar
Released (7.88.1-8ubuntu2.1)
upstream
Released (8.2.0)
Patches:
upstream: https://github.com/curl/curl/commit/0c667188e0c6cda615a0

Severity score breakdown

Parameter Value
Base score 5.0
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality Low
Integrity impact Low
Availability impact Low
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L