Time-of-check Time-of-use (TOCTOU) Race Condition in cURL - CVE-2023-32001

 

Time-of-check Time-of-use (TOCTOU) Race Condition in cURL - CVE-2023-32001

Published: July 21, 2023


Vulnerability identifier: #VU78540
CSH Severity: Low
CVSS v4: 1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32001
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local users to escalate privileges on the system.

The vulnerability exists due to a race condition when calling fopen() on STS and/or alt-svc data to files. A local user can create or rename directory entries in the directory the victim saves their files and abuse the symbolic link behavior to overwrite arbitrary files on the system.


Affected software

cURL
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
openSUSE Leap Micro
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Slackware Linux
Ubuntu
Basesystem Module
openSUSE Leap
openEuler
Fedora
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Platform Automation Toolkit
IBM Engineering Requirements Management DOORS Next
VMware Tanzu Operations Manager
Isolation Segment
VMware Tanzu Application Service for VMs
IBM QRadar WinCollect Agent
EasyApache
IBM Safer Payments
curl (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl3 (Ubuntu package)
curl-debugsource
curl-help
curl-debuginfo
libcurl
libcurl-devel
curl
curl (Debian package)
libcurl4-32bit
libcurl4-debuginfo-32bit
libcurl4-debuginfo
libcurl4
libcurl-devel-32bit
libcurl4-32bit-debuginfo
net-misc/curl
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
Dell EMC VxRail Appliance

How to mitigate CVE-2023-32001

Install updates from vendor's website.

cURL - update to 8.2.0
VMware Tanzu Operations Manager - update to 2.10.61
Isolation Segment - addressed in versions 2.11.40, 2.13.25, 3.0.18, 4.0.10
VMware Tanzu Application Service for VMs - addressed in versions 2.11.46, 2.13.28, 3.0.18, 4.0.10
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
IBM QRadar WinCollect Agent - update to 10.1.8
curl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.19, 7.81.0-1ubuntu1.11, 7.81.0-1ubuntu1.13, 7.85.0-1ubuntu0.6, 7.88.1-8ubuntu2.1
libcurl3-gnutls (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.19, 7.81.0-1ubuntu1.11, 7.81.0-1ubuntu1.13, 7.85.0-1ubuntu0.6, 7.88.1-8ubuntu2.1
libcurl3-nss (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.19, 7.81.0-1ubuntu1.11, 7.81.0-1ubuntu1.13, 7.85.0-1ubuntu0.6, 7.88.1-8ubuntu2.1
libcurl4 (Ubuntu package) - addressed in versions Ubuntu Pro, 7.68.0-1ubuntu2.19, 7.81.0-1ubuntu1.11, 7.81.0-1ubuntu1.13, 7.85.0-1ubuntu0.6, 7.88.1-8ubuntu2.1
libcurl3 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
EMC ViPR SRM - update to 4.10.0.0
EasyApache - update to 4 2023-7-27
IBM Safer Payments - addressed in versions 6.4.2.05, 6.5.0.03, 6.6.0.01
curl-debugsource - update to 7.71.1-30
curl-help - update to 7.71.1-30
curl-debuginfo - update to 7.71.1-30
libcurl - update to 7.71.1-30
libcurl-devel - update to 7.71.1-30
curl - update to 7.71.1-30
curl - addressed in versions 7.85.0-10.fc37, 8.0.1-3.fc38
curl (Debian package) - update to 7.88.1-10+deb12u1
libcurl4-32bit - addressed in versions 8.0.1-11.68.1, 8.0.1-150400.5.26.1
libcurl4-debuginfo-32bit - update to 8.0.1-11.68.1
libcurl4-debuginfo - addressed in versions 8.0.1-11.68.1, 8.0.1-150400.5.26.1
curl - addressed in versions 8.0.1-11.68.1, 8.0.1-150400.5.26.1
libcurl4 - addressed in versions 8.0.1-11.68.1, 8.0.1-150400.5.26.1
curl-debuginfo - addressed in versions 8.0.1-11.68.1, 8.0.1-150400.5.26.1
libcurl-devel - addressed in versions 8.0.1-11.68.1, 8.0.1-150400.5.26.1
curl-debugsource - addressed in versions 8.0.1-11.68.1, 8.0.1-150400.5.26.1
libcurl-devel-32bit - update to 8.0.1-150400.5.26.1
libcurl4-32bit-debuginfo - update to 8.0.1-150400.5.26.1
Dell EMC VxRail Appliance - update to 8.0.120
curl - update to 8.2.0
net-misc/curl - update to 8.3.0-r2

External References

Related Security Bulletins