Advisories ยป MGASA-2023-0288

Updated the curl packages to fix two security vulnerabilities

Publication date: 13 Oct 2023
Modification date: 13 Oct 2023
Type: security
Affected Mageia releases : 8 , 9
CVE: CVE-2023-38545 , CVE-2023-38546

Description

curl/libcurl is vulnerable to a heap buffer overflow in its SOCKS5
support that could be exploited by a remote web server when curl is
configured to use a SOCKS5 proxy with remote hostname resolution.

libcurl is vulnerable to a cookie injection attack where a local
attacker can inject cookies into certain vulnerable applications using
libcurl.
                

References

SRPMS

8/core

9/core