Resource exhaustion in cURL - CVE-2023-38039
Published: September 13, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not limit the size of received headers from a single request that are stored for future reference. A remote attacker can send overly large HTTP responses to the application and consume all memory resources.
Affected software
Oracle Database Server
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
PowerSC
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
macOS
Slackware Linux
Basesystem Module
openSUSE Leap
Anolis OS
Ubuntu
Fedora
Splunk User Behavior Analytics (UBA)
IBM QRadar WinCollect Agent
EasyApache
App Connect Enterprise Certified Container
Dell Secure Connect Gateway
IBM Sterling Secure Proxy
IBM Safer Payments
IBM MQ
IBM Rational ClearCase
IBM Engineering Requirements Management DOORS Next
ObjectScale
Index Engines CyberSense
Dell Data Protection Central
Robotic Process Automation for Cloud Pak
IBM App Connect Enterprise
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
curl
libcurl3-gnutls (Ubuntu package)
curl (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl-devel
curl-debugsource
curl-debuginfo
libcurl4-debuginfo
libcurl4
libcurl4-debuginfo-32bit
libcurl4-32bit
libcurl4-64bit-debuginfo
libcurl-devel-64bit
libcurl4-64bit
libcurl4-32bit-debuginfo
libcurl-devel-32bit
net-misc/curl
libcurl-minimal
curl-doc
libcurl
curl-minimal
jbcs-httpd24-curl (Red Hat package)
JBoss Core Services
RecoverPoint for VMs
Dell EMC VxRail Appliance
Dell EMC NetWorker vProxy
How to mitigate CVE-2023-38039
Oracle Database Server - update to 19.3
Splunk User Behavior Analytics (UBA) - update to 5.4.3
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
IBM QRadar WinCollect Agent - update to 10.1.8
macOS - addressed in versions 12.7.3 21H1015, 13.6.4 22G513, 14.2 23C64
IBM App Connect Enterprise - update to 12.0.10.1
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-34.el7jbcs, 0.4.10-34.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-19.el7jbcs, 1.0.0-19.el8jbcs
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.19-7.el7jbcs, 1.3.19-7.el8jbcs
ObjectScale - update to 1.4.0
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-103.el7jbcs, 1.6.1-103.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-32.el7jbcs, 1.15.19-32.el8jbcs
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-2.el7jbcs, 2.4.24-2.el8jbcs
JBoss Core Services - update to 2.4.57 SP2
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-7.el7jbcs, 2.4.57-7.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-32.el7jbcs, 2.9.3-32.el8jbcs
EasyApache - update to 4 2023-9-20
App Connect Enterprise Certified Container - addressed in versions 5.0.13, 11.0.0
Dell Secure Connect Gateway - update to 5.20.00.10
RecoverPoint for VMs - update to 6.0.SP1.P1
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
IBM Safer Payments - addressed in versions 6.4.2.06, 6.5.0.04, 6.6.0.02
curl - addressed in versions 7.85.0-11.fc37, 8.0.1-4.fc38, 8.2.1-2.fc39
libcurl3-gnutls (Ubuntu package) - update to 7.88.1-8ubuntu2.2
curl (Ubuntu package) - update to 7.88.1-8ubuntu2.2
libcurl4 (Ubuntu package) - update to 7.88.1-8ubuntu2.2
libcurl3-nss (Ubuntu package) - update to 7.88.1-8ubuntu2.2
libcurl-devel - addressed in versions 8.0.1-11.71.1, 8.0.1-150400.5.29.1
curl-debugsource - addressed in versions 8.0.1-11.71.1, 8.0.1-150400.5.29.1
curl-debuginfo - addressed in versions 8.0.1-11.71.1, 8.0.1-150400.5.29.1
curl - addressed in versions 8.0.1-11.71.1, 8.0.1-150400.5.29.1
libcurl4-debuginfo - addressed in versions 8.0.1-11.71.1, 8.0.1-150400.5.29.1
libcurl4 - addressed in versions 8.0.1-11.71.1, 8.0.1-150400.5.29.1
libcurl4-debuginfo-32bit - update to 8.0.1-11.71.1
libcurl4-32bit - addressed in versions 8.0.1-11.71.1, 8.0.1-150400.5.29.1
libcurl4-64bit-debuginfo - update to 8.0.1-150400.5.29.1
libcurl-devel-64bit - update to 8.0.1-150400.5.29.1
libcurl4-64bit - update to 8.0.1-150400.5.29.1
libcurl4-32bit-debuginfo - update to 8.0.1-150400.5.29.1
libcurl-devel-32bit - update to 8.0.1-150400.5.29.1
Dell EMC VxRail Appliance - update to 8.0.120
curl - update to 8.3.0
net-misc/curl - update to 8.3.0-r2
curl - update to 8.3.0-1
Index Engines CyberSense - update to 8.4
libcurl-minimal - update to 8.4.0-1
curl-doc - update to 8.4.0-1
libcurl-devel - update to 8.4.0-1
libcurl - update to 8.4.0-1
curl-minimal - update to 8.4.0-1
curl - update to 8.4.0-1
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.4.0-2.el7jbcs, 8.4.0-2.el8jbcs
IBM MQ - addressed in versions 9.0.0.21, 9.1.0.18, 9.2.0.20, 9.3.0.11, 9.3.4
IBM Rational ClearCase - addressed in versions 9.1.0.6, 10.0.1.1
Dell EMC NetWorker vProxy - addressed in versions 19.9.0.4, 19.10
Dell Data Protection Central - update to 19.10.0-4
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.12
External References
Related Security Bulletins
- Denial of service in cURL
- Ubuntu update for curl
- Slackware Linux update for curl
- Fedora 39 update for curl
- Fedora 38 update for curl
- Fedora 37 update for curl
- SUSE update for curl
- Multiple vulnerabilities in cPanel EasyApache
- SUSE update for curl
- Gentoo update for curl
- Multiple vulnerabilities in Oracle Database Server
- Resource exhaustion in IBM MQ
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- Multiple vulnerabilities in Index Engines CyberSense
- IBM App Connect Enterprise update for cURL
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server 2.4
- Multiple vulnerabilities in Red Hat JBoss Core Services for RHEL 7 and 8
- Multiple vulnerabilities in IBM PowerSC
- App Connect Enterprise Certified Container update for cURL
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Apple macOS Ventura
- Dell EMC NetWorker vProxy update for third-party components
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Dell Data Protection Central update for third-party components
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- Multiple vulnerabilities in IBM Rational ClearCase
- Multiple vulnerabilities in IBM Secure Proxy
- Multiple vulnerabilities in IBM Safer Payments
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Amazon Linux AMI update for curl
- Anolis OS update for curl
- Splunk User Behavior Analytics (UBA) update for third-party components