Missing Encryption of Sensitive Data in cURL - CVE-2023-46219

 

Missing Encryption of Sensitive Data in cURL - CVE-2023-46219

Published: December 6, 2023


Vulnerability identifier: #VU83899
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46219
CWE-ID: CWE-311
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to an error when handling HSTS long file names. When saving HSTS data to an excessively long file name, curl can end up removing all contents from the file, making subsequent requests using that file unaware of the HSTS status they should otherwise use. As a result, a remote attacker can perform MitM attack.


Affected software

cURL
Integrated Data protection Appliance (IDPA)
Data Protection Search
Debian Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Storage Copy Data Management
Cloud Pak for Network Automation
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect Plus Server
NetWorker Management Console (NMC)
Nessus Network Monitor
VMware Horizon Client
LANTIME Operating System Firmware (LTOS)
PowerScale OneFS
Cisco Jabber
Cisco Webex Meetings
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
libcurl4 (Ubuntu package)
curl (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl3-nss (Ubuntu package)
curl
libcurl-devel
curl-debuginfo
curl-debugsource
libcurl
curl-help
curl (Debian package)
libcurl4-debuginfo-32bit
libcurl4-32bit
libcurl4-debuginfo
libcurl4
libcurl-devel-32bit
libcurl4-32bit-debuginfo
libcurl4-64bit
libcurl4-64bit-debuginfo
libcurl-devel-64bit
libcurl-minimal
curl-minimal
curl-doc
jbcs-httpd24-curl (Red Hat package)
net-misc/curl
JBoss Core Services
IBM Cloud Object Storage Systems
EasyApache
IBM QRadar WinCollect Agent
EMC NetWorker Server
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
Dell EMC NetWorker vProxy

How to mitigate CVE-2023-46219

Install updates from vendor's website.

cURL - update to 8.5.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Nessus Network Monitor - update to 6.4.0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
LANTIME Operating System Firmware (LTOS) - update to 7.08.007
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-35.el7jbcs, 0.4.10-35.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-20.el7jbcs, 1.0.0-20.el8jbcs
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.20-3.el7jbcs, 1.3.20-3.el8jbcs
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-104.el7jbcs, 1.6.1-104.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-36.el7jbcs, 1.15.19-36.el8jbcs
Storage Copy Data Management - update to 2.2.24.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-4.el7jbcs, 2.4.24-4.el8jbcs
JBoss Core Services - update to 2.4.57 SP3
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-9.el7jbcs, 2.4.57-9.el8jbcs
Cloud Pak for Network Automation - update to 2.7
Integrated Data protection Appliance (IDPA) - update to 2.7.8 with DP Search 19.6.6
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-34.el7jbcs, 2.9.3-34.el8jbcs
IBM Cloud Object Storage Systems - addressed in versions 3.18.0.40, 3.18.1.45
EasyApache - update to 4 2023-12-13
libcurl4 (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
curl (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
libcurl3-nss (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.21, 7.81.0-1ubuntu1.15, 7.88.1-8ubuntu2.4, 8.2.1-1ubuntu3.2
curl - addressed in versions 7.71.1-32, 7.79.1-25
libcurl-devel - addressed in versions 7.71.1-32, 7.79.1-25
curl-debuginfo - addressed in versions 7.71.1-32, 7.79.1-25
curl-debugsource - addressed in versions 7.71.1-32, 7.79.1-25
libcurl - addressed in versions 7.71.1-32, 7.79.1-25
curl-help - addressed in versions 7.71.1-32, 7.79.1-25
curl (Debian package) - addressed in versions 7.74.0-1.3+deb11u11, 7.88.1-10+deb12u5
curl - addressed in versions 8.0.1-6.fc38, 8.2.1-4.fc39
libcurl4-debuginfo-32bit - update to 8.0.1-11.80.1
libcurl4-32bit - addressed in versions 8.0.1-11.80.1, 8.0.1-150400.5.36.1
curl - addressed in versions 8.0.1-11.80.1, 8.0.1-150400.5.36.1
libcurl4-debuginfo - addressed in versions 8.0.1-11.80.1, 8.0.1-150400.5.36.1
curl-debuginfo - addressed in versions 8.0.1-11.80.1, 8.0.1-150400.5.36.1
curl-debugsource - addressed in versions 8.0.1-11.80.1, 8.0.1-150400.5.36.1
libcurl4 - addressed in versions 8.0.1-11.80.1, 8.0.1-150400.5.36.1
libcurl-devel - addressed in versions 8.0.1-11.80.1, 8.0.1-150400.5.36.1
libcurl-devel-32bit - update to 8.0.1-150400.5.36.1
libcurl4-32bit-debuginfo - update to 8.0.1-150400.5.36.1
libcurl4-64bit - update to 8.0.1-150400.5.36.1
libcurl4-64bit-debuginfo - update to 8.0.1-150400.5.36.1
libcurl-devel-64bit - update to 8.0.1-150400.5.36.1
Storage Protect Client - update to 8.1.23.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.24.0
libcurl-minimal - update to 8.4.0-6
libcurl-devel - update to 8.4.0-6
libcurl - update to 8.4.0-6
curl-minimal - update to 8.4.0-6
curl - update to 8.4.0-6
curl-doc - update to 8.4.0-6
curl - update to 8.5.0-1
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.6.0-3.el7jbcs, 8.6.0-3.el8jbcs
net-misc/curl - update to 8.7.1
PowerScale OneFS - addressed in versions 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0
IBM QRadar WinCollect Agent - update to 10.1.9
Storage Protect Plus Server - update to 10.1.16.3
Data Protection Search - update to 19.6.6
NetWorker Management Console (NMC) - update to 19.10.0.5
EMC NetWorker Server - update to 19.10.0.5
Dell EMC NetWorker vProxy - addressed in versions 19.11.0.5, 19.12.0.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.30, 23.0.2.2
IBM Automation Decision Services - update to 23.0.2.0.2

External References

Related Security Bulletins