SB2024031291 - openEuler 22.03 LTS update for curl 



SB2024031291 - openEuler 22.03 LTS update for curl

Published: March 12, 2024

Security Bulletin ID SB2024031291
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Missing Encryption of Sensitive Data (CVE-ID: CVE-2023-46219)

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to an error when handling HSTS long file names. When saving HSTS data to an excessively long file name, curl can end up removing all contents from the file, making subsequent requests using that file unaware of the HSTS status they should otherwise use. As a result, a remote attacker can perform MitM attack.


Remediation

Install update from vendor's website.