CVE-2023-27533
published 2023-03-30CVE-2023-27533: A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted…
PriorityP353high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.99%
78.4th percentile
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | curl | < curl 7.88.1-7 (bookworm) | curl 7.88.1-7 (bookworm) |
| fedoraproject | fedora | — | — |
| haxx | curl | >= 0 < 7.74.0-1.3+deb11u8 | 7.74.0-1.3+deb11u8 |
| haxx | curl | >= 0 < 7.88.1-7 | 7.88.1-7 |
| haxx | curl | >= 0 < 7.88.1-7 | 7.88.1-7 |
| haxx | curl | >= 0 < 7.88.1-7 | 7.88.1-7 |
| haxx | curl | >= 0 < 7.58.0-2ubuntu3.24 | 7.58.0-2ubuntu3.24 |
| haxx | curl | >= 0 < 7.68.0-1ubuntu2.18 | 7.68.0-1ubuntu2.18 |
| haxx | curl | >= 0 < 7.81.0-1ubuntu1.10 | 7.81.0-1ubuntu1.10 |
| haxx | curl | >= 0 < 7.35.0-1ubuntu2.20+esm15 | 7.35.0-1ubuntu2.20+esm15 |
| haxx | curl | >= 0 < 7.47.0-1ubuntu2.19+esm8 | 7.47.0-1ubuntu2.19+esm8 |
| haxx | curl | 7.0.0 – 7.881 | — |
| https | github.com_curl_curl | — | — |
| msrc | azl3_cmake_3.21.4-10_on_azure_linux_3.0 | — | — |
| msrc | azl3_cmake_3.28.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-14_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.86.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.11.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_cmake_3.21.4-12_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_curl_8.0.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_mysql_8.0.34-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_rust_1.72.0-2_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-02-15
Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-15
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Out-of-bounds Read, Inadequate Encryption Strength, Double Free, Use After Free, NULL Pointer Dereference, Improper Input Validation, Missing Encryption of Sensitive Data, Allocation of Resources Wit
Ubuntu
curl vulnerabilities
vendor_ubuntu·2023-03-27·CVSS 8.8
CVE-2023-27535 [HIGH] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
USN-5964-1 fixed several vulnerabilities in curl. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Harry Sintonen discovered that curl incorrectly handled certain TELNET
connection options. Due to lack of proper input scrubbing, curl could pass
on user name and telnet options to the server as provided, contrary to
expectations. (CVE-2023-27533)
Harry Sintonen discovered that curl incorrectly reused certain FTP
connections. This could lead to the wrong credentials being reused,
contrary to expectations. (CVE-2023-27535)
Harry Sintonen discovered that curl incorrectly reused connections when the
GSS delegation option had been changed. This
Ubuntu
curl vulnerabilities
vendor_ubuntu·2023-03-20·CVSS 8.8
CVE-2023-27533 [HIGH] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Harry Sintonen discovered that curl incorrectly handled certain TELNET
connection options. Due to lack of proper input scrubbing, curl could pass
on user name and telnet options to the server as provided, contrary to
expectations. (CVE-2023-27533)
Harry Sintonen discovered that curl incorrectly handled special tilde
characters when used with SFTP paths. A remote attacker could possibly use
this issue to circumvent filtering. (CVE-2023-27534)
Harry Sintonen discovered that curl incorrectly reused certain FTP
connections. This could lead to the wrong credentials being reused,
contrary to expectations. (CVE-2023-27535)
Harry Sintonen discovered that curl incorrectly reused connections when the
GSS delegation
Red Hat
curl: TELNET option IAC injection
vendor_redhat·2023-03-20·CVSS 8.8
CVE-2023-27533 [HIGH] CWE-75 curl: TELNET option IAC injection
curl: TELNET option IAC injection
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.
Statement: While this vulnerability exists in Curl, the potential impact is to a different component. The overall impact is limited to the telnet component. On its own this flaw has a limited to negligible effect on integrity of the entire system, therefore it has been rat
Microsoft
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server
vendor_msrc·2023-03-14·CVSS 8.8
CVE-2023-27533 [HIGH] CWE-74 A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server
A vulnerability in input validation exists in curl Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
hackerone: hackerone
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.mi
Debian
CVE-2023-27533: curl - A vulnerability in input validation exists in curl <8.0 during communication usi...
vendor_debian·2023·CVSS 8.8
CVE-2023-27533 [HIGH] CVE-2023-27533: curl - A vulnerability in input validation exists in curl <8.0 during communication usi...
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.
Scope: local
bookworm: resolved (fixed in 7.88.1-7)
bullseye: resolved (fixed in 7.74.0-1.3+deb11u8)
forky: resolved (fixed in 7.88.1-7)
sid: resolved (fixed in 7.88.1-7)
trixie: resolved (fixed in 7.88.1-7)
OSV
CVE-2023-27533: A vulnerability in input validation exists in curl <8
osv·2023-03-30·CVSS 8.8
CVE-2023-27533 [HIGH] CVE-2023-27533: A vulnerability in input validation exists in curl <8
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.
GHSA
GHSA-xvw3-6q4f-2gcv: A vulnerability in input validation exists in curl <8
ghsa_unreviewed·2023-03-30
CVE-2023-27533 [HIGH] CWE-74 GHSA-xvw3-6q4f-2gcv: A vulnerability in input validation exists in curl <8
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.
OSV
curl vulnerabilities
osv·2023-03-27·CVSS 8.8
CVE-2023-27533 [HIGH] curl vulnerabilities
curl vulnerabilities
USN-5964-1 fixed several vulnerabilities in curl. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Harry Sintonen discovered that curl incorrectly handled certain TELNET
connection options. Due to lack of proper input scrubbing, curl could pass
on user name and telnet options to the server as provided, contrary to
expectations. (CVE-2023-27533)
Harry Sintonen discovered that curl incorrectly reused certain FTP
connections. This could lead to the wrong credentials being reused,
contrary to expectations. (CVE-2023-27535)
Harry Sintonen discovered that curl incorrectly reused connections when the
GSS delegation option had been changed. This could lead to the option being
reused, contrary to expectatio
OSV
curl vulnerabilities
osv·2023-03-20·CVSS 8.8
CVE-2023-27533 [HIGH] curl vulnerabilities
curl vulnerabilities
Harry Sintonen discovered that curl incorrectly handled certain TELNET
connection options. Due to lack of proper input scrubbing, curl could pass
on user name and telnet options to the server as provided, contrary to
expectations. (CVE-2023-27533)
Harry Sintonen discovered that curl incorrectly handled special tilde
characters when used with SFTP paths. A remote attacker could possibly use
this issue to circumvent filtering. (CVE-2023-27534)
Harry Sintonen discovered that curl incorrectly reused certain FTP
connections. This could lead to the wrong credentials being reused,
contrary to expectations. (CVE-2023-27535)
Harry Sintonen discovered that curl incorrectly reused connections when the
GSS delegation option had been changed. This could lead to the option being
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2023-27533: Telnet option IAC injection
hackerone·2023-03-22·CVSS 8.8
CVE-2023-27533 [HIGH] CVE-2023-27533: Telnet option IAC injection
CVE-2023-27533: Telnet option IAC injection
## Summary:
`CURLOPT_TELNETOPTIONS` allows setting various telnet options for telnet protocol. Due to missing encoding of "Interpret as Command" `IAC` (0xff) character, the attacker who can control these option values can escape out of the telnet subnegotiation and enter arbitrary TELNET commands (*) via the `CURLOPT_TELNETOPTIONS` options. `TTYPE`, `XDISPLOC` and `NEW_ENV` options are affected.
*) TELNET command refers to "TELNET COMMAND STRUCTURE" in RFC 854
## Steps To Reproduce:
1. `curl --telnet-option NEW_ENV=a,b$(echo -ne "\xff\xf0INJECTED") telnet://server`
When inspected with tcpdump:
```
20:57:34.454720 IP x.x.x.x.53864 > y.y.y.y.telnet: Flags [P.], seq 17:37, ack 22, win 2058, options [nop,nop,TS val 1459077881 ecr 3403052525], le
HackerOne
CVE-2023-27533: TELNET option IAC injection
hackerone·2023-03-20·CVSS 8.8
CVE-2023-27533 [HIGH] CVE-2023-27533: TELNET option IAC injection
CVE-2023-27533: TELNET option IAC injection
curl supports communicating using the TELNET protocol and as a part of this it offers users to pass on user name and "telnet options" for the server negotiation.
Due to lack of proper input scrubbing and without it being the documented functionality, curl would pass on user name and telnet options to the server as provided. This could allow users to pass in carefully crafted content that pass on content or do option negotiation without the application intending to do so. In particular if an application for example allows users to provide the data or parts of the data.
## Hackerone report
#1891474
## Impact
Attacker being able to specify TTYPE, XDISPLOC or NEW_ENV values is able to inject unintended TELNET commands to the telnet connection. D
https://hackerone.com/reports/1891474https://lists.debian.org/debian-lts-announce/2023/04/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/https://security.gentoo.org/glsa/202310-12https://security.netapp.com/advisory/ntap-20230420-0011/https://hackerone.com/reports/1891474https://lists.debian.org/debian-lts-announce/2023/04/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/https://security.gentoo.org/glsa/202310-12https://security.netapp.com/advisory/ntap-20230420-0011/
2023-03-30
Published