cbcvebase.
CVE-2023-28320
published 2023-05-26

CVE-2023-28320: A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build…

PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
2.66%
83.7th percentile
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave.

Affected

23 ranges
VendorProductVersion rangeFixed in
applemacos>= 11.0 < 11.7.911.7.9
applemacos>= 12.0 < 12.6.812.6.8
applemacos>= 13.0 < 13.513.5
applemacos_big_sur
applemacos_monterey
applemacos_ventura
debiancurl< curl 7.88.1-10 (bookworm)curl 7.88.1-10 (bookworm)
haxxcurl< 8.1.08.1.0
haxxcurl>= 0 < 7.88.1-107.88.1-10
haxxcurl>= 0 < 7.88.1-107.88.1-10
haxxcurl>= 0 < 7.88.1-107.88.1-10
httpsgithub.com_curl_curl
msrcazl3_cmake_3.21.4-10_on_azure_linux_3.0
msrcazl3_cmake_3.28.2-1_on_azure_linux_3.0
msrcazl3_rust_1.75.0-14_on_azure_linux_3.0
msrcazl3_rust_1.86.0-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.11.1-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-1_on_azure_linux_3.0
msrccbl2_cmake_3.21.4-11_on_cbl_mariner_2.0
msrccbl2_curl_8.2.1-1_on_cbl_mariner_2.0
msrccbl2_mysql_8.0.34-1_on_cbl_mariner_2.0
msrccbl2_rust_1.72.0-2_on_cbl_mariner_2.0
msrccbl2_tensorflow_2.11.1-2_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.