CVE-2023-27533

CWE-75CWE-7413 documents9 sources
Severity
8.8HIGH
EPSS
0.2%
top 59.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30

Description

A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

Debiancurl< 7.74.0-1.3+deb11u8+3
Ubuntucurl< 7.58.0-2ubuntu3.24+4
NVDhaxx/curl7.0.07.881
CVEListV5https://github.com/curl/curlFixed in 8.0.0
NVDsplunk/universal_forwarder8.2.08.2.12+2

Also affects: Fedora 36

🔴Vulnerability Details

5
CVEList
CVE-2023-27533: A vulnerability in input validation exists in curl <82023-03-30
OSV
CVE-2023-27533: A vulnerability in input validation exists in curl <82023-03-30
GHSA
GHSA-xvw3-6q4f-2gcv: A vulnerability in input validation exists in curl <82023-03-30
OSV
curl vulnerabilities2023-03-27
OSV
curl vulnerabilities2023-03-20

📋Vendor Advisories

5
Ubuntu
curl vulnerabilities2023-03-27
Ubuntu
curl vulnerabilities2023-03-20
Red Hat
curl: TELNET option IAC injection2023-03-20
Microsoft
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server2023-03-14
Debian
CVE-2023-27533: curl - A vulnerability in input validation exists in curl <8.0 during communication usi...2023

💬Community

2
HackerOne
CVE-2023-27533: Telnet option IAC injection2023-03-22
HackerOne
CVE-2023-27533: TELNET option IAC injection2023-03-20
CVE-2023-27533 (HIGH CVSS 8.8) | A vulnerability in input validation | cvebase.io