CVE-2023-23916Allocation of Resources Without Limits or Throttling in Curl

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 74.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 23
Latest updateApr 15

Description

An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain" wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5https/github.com_curl_curlFixed in 7.88.0
NVDhaxx/curl7.57.07.88.0
Debianhaxx/curl< 7.74.0-1.3+deb11u7+3
NVDsplunk/universal_forwarder8.2.08.2.12+2

Also affects: Debian Linux 10.0, 11.0, Fedora 36

🔴Vulnerability Details

3
GHSA
GHSA-v8vq-prc2-j6gx: An allocation of resources without limits or throttling vulnerability exists in curl <v72023-02-23
CVEList
CVE-2023-23916: An allocation of resources without limits or throttling vulnerability exists in curl <v72023-02-23
OSV
CVE-2023-23916: An allocation of resources without limits or throttling vulnerability exists in curl <v72023-02-23

📋Vendor Advisories

5
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (cURL) — CVE-2023-239162023-04-15
Ubuntu
curl vulnerabilities2023-02-27
Red Hat
curl: HTTP multi-header compression denial of service2023-02-15
Microsoft
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms meaning that a server response can be compressed multip2023-02-14
Debian
CVE-2023-23916: curl - An allocation of resources without limits or throttling vulnerability exists in ...2023

💬Community

2
HackerOne
HTTP multi-header compression denial of service2023-02-24
HackerOne
CVE-2023-23916: HTTP multi-header compression denial of service2023-02-20
CVE-2023-23916 — Haxx Curl vulnerability | cvebase