PT-2024-1741 · Tiny-Curl+2 · Tiny-Curl+2

Published

2024-01-30

·

Updated

2024-02-26

·

CVE-2023-52071

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions curl versions 8.4.0 through 8.5.0 tiny-curl version 8.4.0
Description The issue is related to an off-by-one out-of-bounds array index in the tool cb wrt component of the curl and tiny-curl utilities. This could allow a remote attacker to disclose protected information. There are reports of increased actor activities targeting this issue.
Recommendations For curl versions 8.4.0 through 8.5.0, update to a version that contains a fix for this issue. For tiny-curl version 8.4.0, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the tool cb wrt component until a patch is available.

Fix

Improper Validation of Array Index

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-2266
BDU:2024-01449
CVE-2023-52071

Affected Products

Alt Linux
Curl
Tiny-Curl