vulnerability

FreeBSD: VID-A4F8BB03-F52F-11ED-9859-080027083A05 (CVE-2023-28322): curl -- multiple vulnerabilities

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
Mar 21, 2023
Added
May 20, 2023
Modified
Jan 28, 2025

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-A4F8BB03-F52F-11ED-9859-080027083A05:




Wei Chong Tan, Harry Sintonen, and Hiroki Kurosawa reports:



This update fixes 4 security vulnerabilities:



Medium CVE-2023-28319: UAF in SSH sha256 fingerprint check. Reported by Wei Chong Tan on 2023-03-21


Low CVE-2023-28320: siglongjmp race condition. Reported by Harry Sintonen on 2023-04-02


Low CVE-2023-28321: IDN wildcard match. Reported by Hiroki Kurosawa on 2023-04-17


Low CVE-2023-28322: more POST-after-PUT confusion. Reported by Hiroki Kurosawa on 2023-04-19





Solution

freebsd-upgrade-package-curl
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.