CVE-2024-2004
published 2024-03-27CVE-2024-2004: When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to…
PriorityP417low3.5CVSS 3.1
AVNACLPRLUIRSUCLINAN
EPSS
1.68%
74.4th percentile
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.se The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has thus assessed this to be low severity bug.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 12.7.6 | 12.7.6 |
| apple | macos | >= 13.0 < 13.6.8 | 13.6.8 |
| apple | macos | >= 14.0 < 14.6 | 14.6 |
| apple | macos_monterey | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_ventura | — | — |
| curl | curl | 7.85.0 – 7.85.0 | — |
| curl | curl | 7.86.0 – 7.86.0 | — |
| curl | curl | 7.87.0 – 7.87.0 | — |
| curl | curl | 7.88.0 – 7.88.0 | — |
| curl | curl | 7.88.1 – 7.88.1 | — |
| curl | curl | 8.0.0 – 8.0.0 | — |
| curl | curl | 8.0.1 – 8.0.1 | — |
| curl | curl | 8.1.0 – 8.1.0 | — |
| curl | curl | 8.1.1 – 8.1.1 | — |
| curl | curl | 8.1.2 – 8.1.2 | — |
| curl | curl | 8.2.0 – 8.2.0 | — |
| curl | curl | 8.2.1 – 8.2.1 | — |
| curl | curl | 8.3.0 – 8.3.0 | — |
| curl | curl | 8.4.0 – 8.4.0 | — |
| curl | curl | 8.5.0 – 8.5.0 | — |
| curl | curl | 8.6.0 – 8.6.0 | — |
| debian | curl | < curl 7.88.1-10+deb12u6 (bookworm) | curl 7.88.1-10+deb12u6 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.13.5LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
osv3.5LOW
vendor_msrc7.8HIGH
vendor_debian3.5LOW
vendor_redhat3.5LOW
vendor_ubuntu3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-11-14
Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateNovember 14, 2024
Alert CodeICSA-24-319-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Improper Input Validation, Improper Check for Unusual or Exceptional Conditions, Out-of-bounds Write, Uncontro
CISA ICS
Siemens SINEMA
cisa_ics·2024-09-12·CVSS 9.8
[CRITICAL] Siemens SINEMA
ICS Advisory
##
Siemens SINEMA
Release DateSeptember 12, 2024
Alert CodeICSA-24-256-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 5.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEMA
- Vulnerabilities: Use After Free, Improper Input Validation, Improper Certificate Validation, Missing Release of Resource after Effective Lifetime, Improper Validation of Certificate with Host Mismatch, Insufficient Sessi
Apple
CVE-2024-2004: macOS Sonoma 14.6
vendor_apple·2024-07-29·CVSS 3.5
CVE-2024-2004 [LOW] CVE-2024-2004: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-2004
Component: CVE-2024-2004
Apple
CVE-2024-2004: macOS Ventura 13.6.8
vendor_apple·2024-07-29·CVSS 3.5
CVE-2024-2004 [LOW] CVE-2024-2004: macOS Ventura 13.6.8
Apple Security Update: About the security content of macOS Ventura 13.6.8
Product: macOS Ventura
Version: 13.6.8
CVE: CVE-2024-2004
Component: CVE-2024-2004
Apple
CVE-2024-2004: macOS Monterey 12.7.6
vendor_apple·2024-07-29·CVSS 3.5
CVE-2024-2004 [LOW] CVE-2024-2004: macOS Monterey 12.7.6
Apple Security Update: About the security content of macOS Monterey 12.7.6
Product: macOS Monterey
Version: 12.7.6
CVE: CVE-2024-2004
Component: CVE-2024-2004
Microsoft
Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability
vendor_msrc·2024-05-14·CVSS 7.8
CVE-2024-26238 [HIGH] CWE-59 Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability
Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: How do I protect myself from this vulnerability?
Customers running Windows 10 version 2004 through 20H2 need to have KB 5001716 installed to be protected from this vulnerability. This update will be downloaded and installed automatically from Windows update on all in-support versions of Windows 10. It is also offered to Windows Update Client for some devices that have not installed the most recent updates. If you are running a version of Windows10 that has reached the end of its support lifecycle, or if you have not installe
Ubuntu
curl vulnerabilities
vendor_ubuntu·2024-04-29·CVSS 3.5
CVE-2024-2398 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
USN-6718-1 fixed vulnerabilities in curl. This update provides the
corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Dan Fandrich discovered that curl would incorrectly use the default set of
protocols when a parameter option disabled all protocols without adding
any, contrary to expectations. This issue only affected Ubuntu 23.10.
(CVE-2024-2004)
It was discovered that curl incorrectly handled memory when limiting the
amount of headers when HTTP/2 server push is allowed. A remote attacker
could possibly use this issue to cause curl to consume resources, leading
to a denial of service. (CVE-2024-2398)
Instructions: In general, a standard system update will make all the necessary chan
Ubuntu
curl vulnerabilities
vendor_ubuntu·2024-03-27·CVSS 3.5
CVE-2024-2004 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Dan Fandrich discovered that curl would incorrectly use the default set of
protocols when a parameter option disabled all protocols without adding
any, contrary to expectations. This issue only affected Ubuntu 23.10.
(CVE-2024-2004)
It was discovered that curl incorrectly handled memory when limiting the
amount of headers when HTTP/2 server push is allowed. A remote attacker
could possibly use this issue to cause curl to consume resources, leading
to a denial of service. (CVE-2024-2398)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
curl: Usage of disabled protocol
vendor_redhat·2024-03-27·CVSS 3.5
CVE-2024-2004 [LOW] CWE-115 curl: Usage of disabled protocol
curl: Usage of disabled protocol
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.se The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has thus assessed this to be low severity bug.
A flaw was found in curl. When a protocol selection parameter disables all protocols without adding any, the default set of prot
Microsoft
Usage of disabled protocol
vendor_msrc·2024-03-12·CVSS 3.5
CVE-2024-2004 [LOW] CWE-436 Usage of disabled protocol
Usage of disabled protocol
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
curl: curl
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azur
Debian
CVE-2024-2004: curl - When a protocol selection parameter option disables all protocols without adding...
vendor_debian·2024·CVSS 3.5
CVE-2024-2004 [LOW] CVE-2024-2004: curl - When a protocol selection parameter option disables all protocols without adding...
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.se The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has thus assessed this to be low severity bug.
Scope: local
bookworm: resolved (fixed in 7.88.1-10+deb12u6)
bullseye: resolved
forky: resolved (fixed in 8.7.1-1)
sid: resolved (fixed in 8.7.1-1)
trixie: resolve
OSV
curl vulnerabilities
osv·2024-04-29·CVSS 3.5
CVE-2024-2004 [LOW] curl vulnerabilities
curl vulnerabilities
USN-6718-1 fixed vulnerabilities in curl. This update provides the
corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Dan Fandrich discovered that curl would incorrectly use the default set of
protocols when a parameter option disabled all protocols without adding
any, contrary to expectations. This issue only affected Ubuntu 23.10.
(CVE-2024-2004)
It was discovered that curl incorrectly handled memory when limiting the
amount of headers when HTTP/2 server push is allowed. A remote attacker
could possibly use this issue to cause curl to consume resources, leading
to a denial of service. (CVE-2024-2398)
GHSA
GHSA-97xx-95pm-5qv6: When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set
ghsa_unreviewed·2024-03-27
CVE-2024-2004 [LOW] CWE-436 GHSA-97xx-95pm-5qv6: When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.se The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has thus assessed this to be low severity bug.
OSV
CVE-2024-2004: When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set
osv·2024-03-27·CVSS 3.5
CVE-2024-2004 [LOW] CVE-2024-2004: When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.se The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has thus assessed this to be low severity bug.
OSV
curl vulnerabilities
osv·2024-03-27·CVSS 3.5
CVE-2024-2004 [LOW] curl vulnerabilities
curl vulnerabilities
Dan Fandrich discovered that curl would incorrectly use the default set of
protocols when a parameter option disabled all protocols without adding
any, contrary to expectations. This issue only affected Ubuntu 23.10.
(CVE-2024-2004)
It was discovered that curl incorrectly handled memory when limiting the
amount of headers when HTTP/2 server push is allowed. A remote attacker
could possibly use this issue to cause curl to consume resources, leading
to a denial of service. (CVE-2024-2398)
Suricata
GPL FTP MDTM overflow attempt
suricata·2010-09-23
CVE-2001-1021 GPL FTP MDTM overflow attempt
GPL FTP MDTM overflow attempt
Rule: alert ftp $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL FTP MDTM overflow attempt"; flow:established,to_server; content:"MDTM"; nocase; isdataat:100,relative; pcre:"/^MDTM\s[^\n]{100}/smi"; reference:bugtraq,9751; reference:cve,2001-1021; reference:cve,2004-0330; reference:nessus,12080; classtype:attempted-admin; sid:2102546; rev:8; metadata:created_at 2010_09_23, cve CVE_2001_1021, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
GPL NETBIOS SMB-DS nddeapi create tree attempt
suricata·2010-09-23
CVE-2004-0206 GPL NETBIOS SMB-DS nddeapi create tree attempt
GPL NETBIOS SMB-DS nddeapi create tree attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"GPL NETBIOS SMB-DS nddeapi create tree attempt"; flow:established,to_server; flowbits:isset,smb.tree.connect.ipc; flowbits:set,smb.tree.create.nddeapi; content:"|00|"; depth:1; content:"|FF|SMB|A2|"; within:5; distance:3; byte_test:1,!&,128,6,relative; content:"|5C|nddeapi|00|"; within:9; distance:78; nocase; reference:bugtraq,11372; reference:cve,2004-0206; classtype:protocol-command-decode; sid:2102930; rev:6; metadata:created_at 2010_09_23, cve CVE_2004_0206, confidence Medium, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_14;)
Suricata
GPL NETBIOS SMB-DS nddeapi unicode create tree attempt
suricata·2010-09-23
CVE-2004-0206 GPL NETBIOS SMB-DS nddeapi unicode create tree attempt
GPL NETBIOS SMB-DS nddeapi unicode create tree attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"GPL NETBIOS SMB-DS nddeapi unicode create tree attempt"; flow:established,to_server; flowbits:isset,smb.tree.connect.ipc; flowbits:set,smb.tree.create.nddeapi; content:"|00|"; depth:1; content:"|FF|SMB|A2|"; within:5; distance:3; byte_test:1,&,128,6,relative; content:"|5C 00|n|00|d|00|d|00|e|00|a|00|p|00|i|00 00 00|"; within:18; distance:78; nocase; reference:bugtraq,11372; reference:cve,2004-0206; classtype:protocol-command-decode; sid:2102931; rev:6; metadata:created_at 2010_09_23, cve CVE_2004_0206, confidence Medium, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_14;)
Suricata
GPL NETBIOS SMB nddeapi andx create tree attempt
suricata·2010-09-23
CVE-2004-0206 GPL NETBIOS SMB nddeapi andx create tree attempt
GPL NETBIOS SMB nddeapi andx create tree attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS SMB nddeapi andx create tree attempt"; flow:established,to_server; flowbits:isset,smb.tree.connect.ipc; flowbits:set,smb.tree.create.nddeapi; content:"|00|"; depth:1; content:"|FF|SMB"; within:4; distance:3; pcre:"/^(\x75|\x2d|\x2f|\x73|\x2e|\x24|\x74)/sR"; byte_test:1,!&,128,6,relative; content:"|A2|"; depth:1; offset:39; byte_jump:2,0,little,relative; content:"|5C|nddeapi|00|"; within:9; distance:51; nocase; reference:bugtraq,11372; reference:cve,2004-0206; classtype:protocol-command-decode; sid:2102956; rev:5; metadata:created_at 2010_09_23, cve CVE_2004_0206, signature_severity Informational, updated_at 2024_03_14;)
Suricata
GPL FTP RETR overflow attempt
suricata·2010-09-23
CVE-2003-0466 GPL FTP RETR overflow attempt
GPL FTP RETR overflow attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 21 (msg:"GPL FTP RETR overflow attempt"; flow:established,to_server; content:"RETR"; nocase; isdataat:100,relative; pcre:"/^RETR\s[^\n]{100}/smi"; reference:bugtraq,8315; reference:cve,2003-0466; reference:cve,2004-0287; reference:cve,2004-0298; classtype:attempted-admin; sid:2102392; rev:9; metadata:created_at 2010_09_23, cve CVE_2003_0466, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
GPL NETBIOS SMB nddeapi unicode create tree attempt
suricata·2010-09-23
CVE-2004-0206 GPL NETBIOS SMB nddeapi unicode create tree attempt
GPL NETBIOS SMB nddeapi unicode create tree attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS SMB nddeapi unicode create tree attempt"; flow:established,to_server; flowbits:isset,smb.tree.connect.ipc; flowbits:set,smb.tree.create.nddeapi; content:"|00|"; depth:1; content:"|FF|SMB|A2|"; within:5; distance:3; byte_test:1,&,128,6,relative; content:"|5C 00|n|00|d|00|d|00|e|00|a|00|p|00|i|00 00 00|"; within:18; distance:78; nocase; reference:bugtraq,11372; reference:cve,2004-0206; classtype:protocol-command-decode; sid:2102929; rev:6; metadata:created_at 2010_09_23, cve CVE_2004_0206, signature_severity Informational, updated_at 2024_03_14;)
Suricata
GPL NETBIOS SMB nddeapi create tree attempt
suricata·2010-09-23
CVE-2004-0206 GPL NETBIOS SMB nddeapi create tree attempt
GPL NETBIOS SMB nddeapi create tree attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS SMB nddeapi create tree attempt"; flow:established,to_server; flowbits:isset,smb.tree.connect.ipc; flowbits:set,smb.tree.create.nddeapi; content:"|00|"; depth:1; content:"|FF|SMB|A2|"; within:5; distance:3; byte_test:1,!&,128,6,relative; content:"|5C|nddeapi|00|"; within:9; distance:78; nocase; reference:bugtraq,11372; reference:cve,2004-0206; classtype:protocol-command-decode; sid:2102928; rev:6; metadata:created_at 2010_09_23, cve CVE_2004_0206, signature_severity Informational, updated_at 2024_03_14;)
Suricata
GPL FTP invalid MDTM command attempt
suricata·2010-09-23
CVE-2001-1021 GPL FTP invalid MDTM command attempt
GPL FTP invalid MDTM command attempt
Rule: alert ftp $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL FTP invalid MDTM command attempt"; flow:established,to_server; content:"MDTM"; fast_pattern; nocase; pcre:"/^MDTM \d+[-+]\D/smi"; reference:bugtraq,9751; reference:cve,2001-1021; reference:cve,2004-0330; classtype:attempted-admin; sid:2102416; rev:9; metadata:created_at 2010_09_23, cve CVE_2001_1021, signature_severity Unknown, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
GPL NETBIOS SMB nddeapi unicode andx create tree attempt
suricata·2010-09-23
CVE-2004-0206 GPL NETBIOS SMB nddeapi unicode andx create tree attempt
GPL NETBIOS SMB nddeapi unicode andx create tree attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS SMB nddeapi unicode andx create tree attempt"; flow:established,to_server; flowbits:isset,smb.tree.connect.ipc; flowbits:set,smb.tree.create.nddeapi; content:"|00|"; depth:1; content:"|FF|SMB"; within:4; distance:3; pcre:"/^(\x75|\x2d|\x2f|\x73|\x2e|\x24|\x74)/sR"; byte_test:1,&,128,6,relative; content:"|A2|"; depth:1; offset:39; byte_jump:2,0,little,relative; content:"|5C 00|n|00|d|00|d|00|e|00|a|00|p|00|i|00 00 00|"; within:18; distance:51; nocase; reference:bugtraq,11372; reference:cve,2004-0206; classtype:protocol-command-decode; sid:2102957; rev:5; metadata:created_at 2010_09_23, cve CVE_2004_0206, signature_severity Informational, updated_at 2024_03_14;)
Suricata
ET SNMP Attempted TCP Access Attempt to Cisco IOS 12.1 Hidden Read/Write Community String cable-docsis
suricata·2010-07-30
CVE-2004-1776 ET SNMP Attempted TCP Access Attempt to Cisco IOS 12.1 Hidden Read/Write Community String cable-docsis
ET SNMP Attempted TCP Access Attempt to Cisco IOS 12.1 Hidden Read/Write Community String cable-docsis
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 161 (msg:"ET SNMP Attempted TCP Access Attempt to Cisco IOS 12.1 Hidden Read/Write Community String cable-docsis"; flow:established,to_server; content:"cable-docsis"; nocase; reference:url,www.cisco.com/warp/public/707/cisco-sa-20010228-ios-snmp-community.shtml; reference:url,www.iss.net/security_center/reference/vuln/cisco-ios-cable-docsis.htm; reference:url,www.kb.cert.org/vuls/id/840665; reference:cve,2004-1776; classtype:attempted-admin; sid:2011014; rev:3; metadata:created_at 2010_07_30, cve CVE_2004_1776, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_06;)
No public exploits indexed.
HackerOne
Usage of disabled protocol in curl
hackerone·2024-03-29·CVSS 3.5
[LOW] Usage of disabled protocol in curl
Usage of disabled protocol in curl
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled.
curl --proto -all,-http http://curl.se
The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has thus assessed this to be low severity bug.
## Impact
Requests can be sent on an unencrypted link even though the application explicitly disabled that.
CVE-2024-2004
HackerOne
CVE-2024-2004: Usage of disabled protocol
hackerone·2024-03-27·CVSS 3.5
CVE-2024-2004 [LOW] CVE-2024-2004: Usage of disabled protocol
CVE-2024-2004: Usage of disabled protocol
## Summary:
` --proto` in some circumstances ENABLES all protocols after being given `-all`, potentially leading to sending sensitive data over an unencrypted channel.
## Steps To Reproduce:
`curl -Ivs --proto -all,-http http://curl.se`
This command should result in `curl: (1) Protocol "http" disabled` but it actually succeeds.
## Supporting Material/References:
The example command above performs a request to curl.se over http, despite being http support being disabled, both implicitly (-all) and explicitly (-http). It appears that a `--proto` string starting with `-all` and only ever removes protocols without adding them fails in this way. For example:
Example failure scenarios (allowing ALL protocols to go through):
```
--proto -all
--proto -
Bugzilla
CVE-2024-2004 curl: Usage of disabled protocol
bugzilla·2024-03-20·CVSS 3.5
CVE-2024-2004 [LOW] CVE-2024-2004 curl: Usage of disabled protocol
CVE-2024-2004 curl: Usage of disabled protocol
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled.
curl --proto -all,-http http://curl.se
The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has thus assessed this to be low severity bug.
This flaw is also accessible using the curl command line tool.
Reference:
https://curl.se/docs/CVE-2024-2004.ht
Bugzilla
CVE-2023-25775 kernel: irdma: Improper access control
bugzilla·2023-08-11·CVSS 9.8
CVE-2023-25775 [CRITICAL] CVE-2023-25775 kernel: irdma: Improper access control
CVE-2023-25775 kernel: irdma: Improper access control
Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
References:
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00794.html
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2231416]
---
This was fixed for Fedora with the 6.4.16 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2024:2003 https://access.redhat.com/errata/RHSA-2024:2003
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2024:2004 https://
http://seclists.org/fulldisclosure/2024/Jul/18http://seclists.org/fulldisclosure/2024/Jul/19http://seclists.org/fulldisclosure/2024/Jul/20http://www.openwall.com/lists/oss-security/2024/03/27/1https://curl.se/docs/CVE-2024-2004.htmlhttps://curl.se/docs/CVE-2024-2004.jsonhttps://hackerone.com/reports/2384833https://lists.fedoraproject.org/archives/list/[email protected]/message/2D44YLAUFJU6BZ4XFG2FYV7SBKXB5IZ6/https://lists.fedoraproject.org/archives/list/[email protected]/message/GMD6UYKCCRCYETWQZUJ65ZRFULT6SHLI/https://security.netapp.com/advisory/ntap-20240524-0006/https://support.apple.com/kb/HT214118https://support.apple.com/kb/HT214119https://support.apple.com/kb/HT214120http://seclists.org/fulldisclosure/2024/Jul/18http://seclists.org/fulldisclosure/2024/Jul/19http://seclists.org/fulldisclosure/2024/Jul/20http://www.openwall.com/lists/oss-security/2024/03/27/1https://curl.se/docs/CVE-2024-2004.htmlhttps://curl.se/docs/CVE-2024-2004.jsonhttps://hackerone.com/reports/2384833https://lists.fedoraproject.org/archives/list/[email protected]/message/2D44YLAUFJU6BZ4XFG2FYV7SBKXB5IZ6/https://lists.fedoraproject.org/archives/list/[email protected]/message/GMD6UYKCCRCYETWQZUJ65ZRFULT6SHLI/https://security.netapp.com/advisory/ntap-20240524-0006/https://support.apple.com/kb/HT214118https://support.apple.com/kb/HT214119https://support.apple.com/kb/HT214120
2024-03-27
Published