PT-2023-2341 · Libcurl+11 · Libcurl+11

Nyymi

·

Published

2023-03-20

·

Updated

2026-05-18

·

CVE-2023-27535

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions libcurl versions prior to 8.0.0
Description An authentication bypass issue exists in the FTP connection reuse feature of libcurl. This issue can result in wrong credentials being used during subsequent transfers, potentially allowing unauthorized access to sensitive information. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT FTP ACCOUNT, CURLOPT FTP ALTERNATIVE TO USER, CURLOPT FTP SSL CCC, and CURLOPT USE SSL were not included in the configuration match checks, causing them to match too easily.
Recommendations For libcurl versions prior to 8.0.0, consider disabling the FTP connection reuse feature as a temporary workaround until a patch is available. Restrict access to sensitive information by minimizing the use of FTP connections. Avoid using the CURLOPT FTP ACCOUNT, CURLOPT FTP ALTERNATIVE TO USER, CURLOPT FTP SSL CCC, and CURLOPT USE SSL settings in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2650
ALSA-2023:3106
ALT-PU-2023-1475
ALT-PU-2023-1501
ALT-PU-2023-5727
AZL-25787
AZL-25805
AZL-25811
AZL-25846
AZL-34611
AZL-38512
BDU:2023-02106
CESA-2023_3106
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2023-27535
DLA-3398-1
MGASA-2023-0263
OESA-2023-1193
OESA-2023-1194
OESA-2023-1195
OESA-2023-1196
OPENSUSE-SU-2024:12812-1
RHSA-2023:2650
RHSA-2023:3106
RHSA-2023_2650
RHSA-2023_3106
RHSA-2024:0428
RLSA-2023:3106
SUSE-SU-2023:0865-1
SUSE-SU-2023:1582-1
SUSE-SU-2023:1711-1
SUSE-SU-2023:2226-1
SUSE-SU-2023:2228-1
USN-5964-1
USN-5964-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Libcurl