ALSA-2024:1601
Dashboard / Vulnerabilities / ALSA-2024:1601
ALSA-2024:1601
Summary: Moderate: curl security and bug fix update
Details: The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP. Security Fix(es): * curl: information disclosure by exploiting a mixed case flaw (CVE-2023-46218) * curl: more POST-after-PUT confusion (CVE-2023-28322) * curl: cookie injection with none file (CVE-2023-38546) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * libssh (curl sftp) not trying password auth (BZ#2240033) * libssh: cap SFTP packet size sent (AlmaLinux-5485)
References: https://access.redhat.com/errata/RHSA-2024:1601, https://access.redhat.com/security/cve/CVE-2023-28322, https://access.redhat.com/security/cve/CVE-2023-38546, https://access.redhat.com/security/cve/CVE-2023-46218, https://bugzilla.redhat.com/2196793, https://bugzilla.redhat.com/2241938, https://bugzilla.redhat.com/2252030, https://errata.almalinux.org/8/ALSA-2024-1601.html
Affected packages
Package
Name: curl
Purl: pkg:rpm/almalinux/curl
Affected ranges
Type: ECOSYSTEM
Events:
