Project Subscriptions
| Vendors | Products |
|---|---|
|
Broadcom
Subscribe
|
Brocade Fabric Operating System Firmware
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Haxx
Subscribe
|
Libcurl
Subscribe
|
|
Netapp
Subscribe
|
|
|
Redhat
Subscribe
|
Enterprise Linux
Subscribe
|
|
Splunk
Subscribe
|
Universal Forwarder
Subscribe
|
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3398-1 | curl security update |
EUVD |
EUVD-2023-31293 | An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection. |
Ubuntu USN |
USN-5964-1 | curl vulnerabilities |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 09 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-06-09T14:52:08.739Z
Reserved: 2023-03-02T00:00:00.000Z
Link: CVE-2023-27538
Updated: 2024-08-02T12:16:35.616Z
Status : Modified
Published: 2023-03-30T20:15:07.677
Modified: 2025-06-09T15:15:29.150
Link: CVE-2023-27538
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN