PT-2023-2344 · Libcurl+11 · Libcurl+11

Harry Sintonen

·

Publicado

2023-03-20

·

Atualizado

2026-05-18

·

CVE-2023-27536

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions libcurl versions prior to 8.0.0
Description An authentication bypass issue exists in the connection reuse feature of libcurl, affecting krb5/kerberos/negotiate/GSSAPI transfers. This is due to a failure to check for changes in the CURLOPT GSSAPI DELEGATION option, potentially resulting in unauthorized access to sensitive information. The issue allows previously established connections to be reused with incorrect user permissions.
Recommendations For libcurl versions prior to 8.0.0, the safest option is to not reuse connections if the CURLOPT GSSAPI DELEGATION option has been changed. As a temporary workaround, consider disabling connection reuse until a patch is available. Restrict access to krb5/kerberos/negotiate/GSSAPI transfers to minimize the risk of exploitation. Avoid using the CURLOPT GSSAPI DELEGATION option in affected transfers until the issue is resolved.

Exploit

Correção

DoS

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2023:4523
ALSA-2023:6679
ALT-PU-2023-1475
ALT-PU-2023-1501
ALT-PU-2023-5727
AZL-25785
AZL-25802
AZL-25809
AZL-25845
AZL-34606
AZL-38476
BDU:2023-02106
BDU:2023-02109
CESA-2023_4523
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2023-27536
DLA-3398-1
MGASA-2023-0263
OESA-2023-1193
OESA-2023-1194
OESA-2023-1195
OESA-2023-1196
OPENSUSE-SU-2024:12812-1
RHSA-2023:4523
RHSA-2023:6679
RHSA-2023_4523
RHSA-2023_6679
RHSA-2024:0428
RLSA-2023:4523
SUSE-SU-2023:0865-1
SUSE-SU-2023:1582-1
SUSE-SU-2023:1711-1
SUSE-SU-2023:2226-1
SUSE-SU-2023:2228-1
USN-5964-1
USN-5964-2

Produtos afetados

Alt Linux
Almalinux
Astra Linux
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Libcurl