curl-7.76.1-23.el9.2
エラータID: AXSA:2023-6313:11
Release date:
Tuesday, August 8, 2023 - 12:51
Subject:
curl-7.76.1-23.el9.2
Affected Channels:
MIRACLE LINUX 9 for x86_64
Severity:
Moderate
Description:
The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.
Security Fix(es):
* curl: IDN wildcard match may lead to Improper Cerificate Validation (CVE-2023-28321)
* curl: more POST-after-PUT confusion (CVE-2023-28322)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2023-28321
An improper certificate validation vulnerability exists in curl
Solution:
Update packages.
CVEs:
CVE-2023-28321
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`.
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would match IDN (International Domain Name) hosts incorrectly and could as a result accept patterns that otherwise should mismatch. IDN hostnames are converted to puny code before used for certificate checks. Puny coded names always start with `xn--` and should not be allowed to pattern match, but the wildcard check in curl could still check for `x*`, which would match even though the IDN name most likely contained nothing even resembling an `x`.
CVE-2023-28322
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.
Additional Info:
N/A
Download:
SRPMS
- curl-7.76.1-23.el9.2.src.rpm
MD5: 4df48e98413a6739a0385c29e8474986
SHA-256: a63010ee2812c31f666722f85f6bfcb480eae579b3660177e7abffb21d7d9652
Size: 2.40 MB
Asianux Server 9 for x86_64
- curl-7.76.1-23.el9.2.x86_64.rpm
MD5: 088f3c9e7a093196abe39d23990e4b0c
SHA-256: 71a23c52eaa687e4cbe18f6cb75e3f7582670b15f7a44e0f015469054925f0dc
Size: 293.34 kB - curl-minimal-7.76.1-23.el9.2.x86_64.rpm
MD5: 993fd8feb0e7487285ede354a05a79a4
SHA-256: b797880234d3bd512ae7d99dd09cdf55d47bd669fcab203da8467f5952780e04
Size: 126.98 kB - libcurl-7.76.1-23.el9.2.i686.rpm
MD5: 10fe2a37dfcc4ff57cb141abe9bad87e
SHA-256: 59ed70df97892c2c9ba5bcd72a8a8f88748e4011277c47a1fd1402b004230168
Size: 309.97 kB - libcurl-7.76.1-23.el9.2.x86_64.rpm
MD5: a805fa79d74011bb7ab335d2b64d32a2
SHA-256: d7faf97b512215c882c16d22bdfa347e0cdc9946a3d1a48477f6a58a9edc2bf9
Size: 283.56 kB - libcurl-devel-7.76.1-23.el9.2.i686.rpm
MD5: e6f8957c194debe9f1eec465a73bb79c
SHA-256: da144d3a20a64965a776c84c07015326f53f841206e4847217b6af0360fa6949
Size: 848.89 kB - libcurl-devel-7.76.1-23.el9.2.x86_64.rpm
MD5: cfb18c18ba3dcddfbcdb94871a8d5c1d
SHA-256: f1cd706b2d0876c4a8f4111c65111b3d2697d93ef810eb761fe5d4de0e69e2b9
Size: 848.82 kB - libcurl-minimal-7.76.1-23.el9.2.i686.rpm
MD5: 8b35bd7877f2c3dca2d6a8fe69805e11
SHA-256: d0dab7c24b0a42f9709afc32f0cb37a54daa208103bf443d07b07542bebb0f60
Size: 245.15 kB - libcurl-minimal-7.76.1-23.el9.2.x86_64.rpm
MD5: eda92892d27fab2189ec517e17ce0cf2
SHA-256: a1234cb0f2e9fbe245709494f6cd80aecbe70d94eb435f3d2fb0baec13a729ad
Size: 225.89 kB