CVE-2022-27781

Description

libcurl provides the CURLOPT_CERTINFO option to allow applications torequest details to be returned about a servers certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.077

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Curl For Windows 7.83.0Windows
Multiple vulnerabilities are fixed in Curl For Windows 7.83.1Windows
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.81.0-1ubuntu1.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.81.0-1ubuntu1.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.58.0-2ubuntu3.19_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.58.0-2ubuntu3.19_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.68.0-1ubuntu2.12_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.68.0-1ubuntu2.12_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.74.0-1.3ubuntu2.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) curl_7.74.0-1.3ubuntu2.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.81.0-1ubuntu1.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.81.0-1ubuntu1.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.58.0-2ubuntu3.19_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.58.0-2ubuntu3.19_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.68.0-1ubuntu2.12_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.68.0-1ubuntu2.12_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.74.0-1.3ubuntu2.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl4_7.74.0-1.3ubuntu2.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.81.0-1ubuntu1.6_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.81.0-1ubuntu1.6_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.58.0-2ubuntu3.21_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.58.0-2ubuntu3.21_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.68.0-1ubuntu2.14_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.68.0-1ubuntu2.14_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.74.0-1.3ubuntu2.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-nss_7.74.0-1.3ubuntu2.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.81.0-1ubuntu1.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.81.0-1ubuntu1.3_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.58.0-2ubuntu3.19_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.58.0-2ubuntu3.19_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.68.0-1ubuntu2.12_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.68.0-1ubuntu2.12_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.74.0-1.3ubuntu2.3_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-5412-1) libcurl3-gnutls_7.74.0-1.3ubuntu2.3_amd64.debLinux
SUSE-SU-2022:1805-1(SUSE Linux Enterprise Server 12-SP5 ) curl-7.60.0-11.40.2.x86_64.rpmLinux
SUSE-SU-2022:1805-1(SUSE Linux Enterprise Server 12-SP5 ) curl-debuginfo-7.60.0-11.40.2.x86_64.rpmLinux
SUSE-SU-2022:1805-1(SUSE Linux Enterprise Server 12-SP5 ) curl-debugsource-7.60.0-11.40.2.x86_64.rpmLinux
SUSE-SU-2022:1805-1(SUSE Linux Enterprise Server 12-SP5 ) libcurl4-7.60.0-11.40.2.x86_64.rpmLinux
SUSE-SU-2022:1805-1(SUSE Linux Enterprise Server 12-SP5 ) libcurl4-32bit-7.60.0-11.40.2.x86_64.rpmLinux
SUSE-SU-2022:1805-1(SUSE Linux Enterprise Server 12-SP5 ) libcurl4-debuginfo-7.60.0-11.40.2.x86_64.rpmLinux
SUSE-SU-2022:1805-1(SUSE Linux Enterprise Server 12-SP5 ) libcurl4-debuginfo-32bit-7.60.0-11.40.2.x86_64.rpmLinux
curl security update(DSA-5197-1) curl_7.74.0-1.3+deb11u2_amd64.debLinux
SUSE-SU-2023:4614-1(SUSE Linux Enterprise Server 12 SP5 ) java-1_8_0-ibm-1.8.0_sr8.15-30.117.1.x86_64.rpmLinux
SUSE-SU-2023:4614-1(SUSE Linux Enterprise Server 12 SP5 ) java-1_8_0-ibm-alsa-1.8.0_sr8.15-30.117.1.x86_64.rpmLinux
SUSE-SU-2023:4614-1(SUSE Linux Enterprise Server 12 SP5 ) java-1_8_0-ibm-devel-1.8.0_sr8.15-30.117.1.x86_64.rpmLinux
SUSE-SU-2023:4614-1(SUSE Linux Enterprise Server 12 SP5 ) java-1_8_0-ibm-plugin-1.8.0_sr8.15-30.117.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234