PT-2024-1741 · Tiny-Curl+2 · Tiny-Curl+2
Published
2024-01-30
·
Updated
2024-02-26
·
CVE-2023-52071
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
curl versions 8.4.0 through 8.5.0
tiny-curl version 8.4.0
Description
The issue is related to an off-by-one out-of-bounds array index in the
tool cb wrt component of the curl and tiny-curl utilities. This could allow a remote attacker to disclose protected information. There are reports of increased actor activities targeting this issue.Recommendations
For curl versions 8.4.0 through 8.5.0, update to a version that contains a fix for this issue.
For tiny-curl version 8.4.0, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting access to the
tool cb wrt component until a patch is available.Fix
Improper Validation of Array Index
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Curl
Tiny-Curl