Alerts This Week
Warning Icon 1 758
Alerts This Week
Warning Icon 1 758

Ubuntu 18.04 LTS: USN-6237-3 Moderate Curl Security Threats

ubuntu
Calendar Grey September 11, 2023
Dist Ubuntu Esm H88
Recently addressed several curl-related vulnerabilities in Ubuntu notifications. Please find below the update instructions and detailed information regarding the latest security discoveries.
Several security issues were fixed in curl.

Summary

Several security issues were fixed in curl.

Software Description:

- curl: HTTP, HTTPS, and FTP client and client libraries

Details:

USN-6237-1 fixed several vulnerabilities in curl. This update provides the

corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and

Ubuntu 18.04 LTS.

Original advisory details:

 Hiroki Kurosawa discovered that curl incorrectly handled validating

certain

 certificate wildcards. A remote attacker could possibly use this issue to

 spoof certain website certificates using IDN hosts. (CVE-2023-28321)

 Hiroki Kurosawa discovered that curl incorrectly handled callbacks when

 certain options are set by applications. This could cause applications

 using curl to misbehave, resulting in information disclosure, or a denial

 of service. (CVE-2023-28322)

 It was discovered that curl incorrectly handled saving cookies to files. A

 local attacker could possibly use this issue to create or overwrite files.

...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
   curl                            7.58.0-2ubuntu3.24+esm1
   libcurl3-gnutls                 7.58.0-2ubuntu3.24+esm1
   libcurl3-nss                    7.58.0-2ubuntu3.24+esm1
   libcurl4                        7.58.0-2ubuntu3.24+esm1

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
   curl                            7.47.0-1ubuntu2.19+esm9
   libcurl3                        7.47.0-1ubuntu2.19+esm9
   libcurl3-gnutls                 7.47.0-1ubuntu2.19+esm9
   libcurl3-nss                    7.47.0-1ubuntu2.19+esm9

Ubuntu 14.04 LTS (Available with Ubuntu Pro):
   curl                            7.35.0-1ubuntu2.20+esm16
   libcurl3                        7.35.0-1ubuntu2.20+esm16
   libcurl3-gnutls                 7.35.0-1ubuntu2.20+esm16
   libcurl3-nss                    7.35.0-1ubuntu2.20+esm16

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-6237-3

  https://ubuntu.com/security/notices/USN-6237-1

  CVE-2023-28321, CVE-2023-28322

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-6237-3

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here