Missing Encryption of Sensitive Data in cURL - CVE-2023-46219
Published: December 6, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to an error when handling HSTS long file names. When saving HSTS data to an excessively long file name, curl can end
up removing all contents from the file, making subsequent requests using that file
unaware of the HSTS status they should otherwise use. As a result, a remote attacker can perform MitM attack.
Affected software
Integrated Data protection Appliance (IDPA)
Data Protection Search
Debian Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Storage Copy Data Management
Cloud Pak for Network Automation
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect Plus Server
NetWorker Management Console (NMC)
Nessus Network Monitor
VMware Horizon Client
LANTIME Operating System Firmware (LTOS)
PowerScale OneFS
Cisco Jabber
Cisco Webex Meetings
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
libcurl4 (Ubuntu package)
curl (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl3-nss (Ubuntu package)
curl
libcurl-devel
curl-debuginfo
curl-debugsource
libcurl
curl-help
curl (Debian package)
libcurl4-debuginfo-32bit
libcurl4-32bit
libcurl4-debuginfo
libcurl4
libcurl-devel-32bit
libcurl4-32bit-debuginfo
libcurl4-64bit
libcurl4-64bit-debuginfo
libcurl-devel-64bit
libcurl-minimal
curl-minimal
curl-doc
jbcs-httpd24-curl (Red Hat package)
net-misc/curl
JBoss Core Services
IBM Cloud Object Storage Systems
EasyApache
IBM QRadar WinCollect Agent
EMC NetWorker Server
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
Dell EMC NetWorker vProxy
How to mitigate CVE-2023-46219
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Nessus Network Monitor - update to 6.4.0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
LANTIME Operating System Firmware (LTOS) - update to 7.08.007
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-35.el7jbcs, 0.4.10-35.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-20.el7jbcs, 1.0.0-20.el8jbcs
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.20-3.el7jbcs, 1.3.20-3.el8jbcs
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-104.el7jbcs, 1.6.1-104.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-36.el7jbcs, 1.15.19-36.el8jbcs
Storage Copy Data Management - update to 2.2.24.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-4.el7jbcs, 2.4.24-4.el8jbcs
JBoss Core Services - update to 2.4.57 SP3
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-9.el7jbcs, 2.4.57-9.el8jbcs
Cloud Pak for Network Automation - update to 2.7
Integrated Data protection Appliance (IDPA) - update to 2.7.8 with DP Search 19.6.6
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-34.el7jbcs, 2.9.3-34.el8jbcs
IBM Cloud Object Storage Systems - addressed in versions 3.18.0.40, 3.18.1.45
EasyApache - update to 4 2023-12-13
libcurl4 (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
curl (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
libcurl3-nss (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
curl - addressed in versions 7.71.1-32, 7.79.1-25
libcurl-devel - addressed in versions 7.71.1-32, 7.79.1-25
curl-debuginfo - addressed in versions 7.71.1-32, 7.79.1-25
curl-debugsource - addressed in versions 7.71.1-32, 7.79.1-25
libcurl - addressed in versions 7.71.1-32, 7.79.1-25
curl-help - addressed in versions 7.71.1-32, 7.79.1-25
curl (Debian package) - addressed in versions 7.74.0-1.3+deb11u11, 7.88.1-10+deb12u5
curl - addressed in versions 8.0.1-6.fc38, 8.2.1-4.fc39
libcurl4-debuginfo-32bit - update to 8.0.1-11.80.1
libcurl4-32bit - addressed in versions 8.0.1-11.80.1, 8.0.1-150400.5.36.1
curl - addressed in versions 8.0.1-11.80.1, 8.0.1-150400.5.36.1
libcurl4-debuginfo - addressed in versions 8.0.1-11.80.1, 8.0.1-150400.5.36.1
curl-debuginfo - addressed in versions 8.0.1-11.80.1, 8.0.1-150400.5.36.1
curl-debugsource - addressed in versions 8.0.1-11.80.1, 8.0.1-150400.5.36.1
libcurl4 - addressed in versions 8.0.1-11.80.1, 8.0.1-150400.5.36.1
libcurl-devel - addressed in versions 8.0.1-11.80.1, 8.0.1-150400.5.36.1
libcurl-devel-32bit - update to 8.0.1-150400.5.36.1
libcurl4-32bit-debuginfo - update to 8.0.1-150400.5.36.1
libcurl4-64bit - update to 8.0.1-150400.5.36.1
libcurl4-64bit-debuginfo - update to 8.0.1-150400.5.36.1
libcurl-devel-64bit - update to 8.0.1-150400.5.36.1
Storage Protect Client - update to 8.1.23.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.24.0
libcurl-minimal - update to 8.4.0-6
libcurl-devel - update to 8.4.0-6
libcurl - update to 8.4.0-6
curl-minimal - update to 8.4.0-6
curl - update to 8.4.0-6
curl-doc - update to 8.4.0-6
curl - update to 8.5.0-1
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.6.0-3.el7jbcs, 8.6.0-3.el8jbcs
net-misc/curl - update to 8.7.1
PowerScale OneFS - addressed in versions 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0
IBM QRadar WinCollect Agent - update to 10.1.9
Storage Protect Plus Server - update to 10.1.16.3
Data Protection Search - update to 19.6.6
NetWorker Management Console (NMC) - update to 19.10.0.5
EMC NetWorker Server - update to 19.10.0.5
Dell EMC NetWorker vProxy - addressed in versions 19.11.0.5, 19.12.0.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.30, 23.0.2.2
IBM Automation Decision Services - update to 23.0.2.0.2
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Ubuntu update for curl
- SUSE update for curl
- SUSE update for curl
- Fedora 39 update for curl
- Fedora 38 update for curl
- cPanel EasyApache update for libcurl
- Debian update for curl
- Multiple vulnerabilities in IBM Cloud Object System
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM Automation Decision Services
- openEuler 20.03 LTS SP1 update for curl
- openEuler 20.03 LTS SP3 update for curl
- openEuler 22.03 LTS update for curl
- openEuler 22.03 LTS SP1 update for curl
- openEuler 22.03 LTS SP2 update for curl
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server 2.4
- Multiple vulnerabilities in Red Hat JBoss Core Services for RHEL 7 and 8
- Tenable Nessus Network Monitor update for third-party components
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in IBM Storage Protect Client
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Amazon Linux AMI update for curl
- Gentoo update for curl
- Multiple vulnerabilities in IBM Storage Protect Plus
- Multiple vulnerabilities in IBM Storage Protect for Virtual Environments: Data Protection for Microsoft Hyper-V
- Multiple vulnerabilities in Dell NetWorker And NetWorker Management Console
- Multiple vulnerabilities in Dell PowerScale OneFS
- Anolis OS update for curl
- Dell EMC NetWorker vProxy update for third-party components
- Meinberg LANTIME firmware update for third-party components (January 2024)
- Multiple vulnerabilities in Dell Data Protection Search