CLSA-2023-1681491348
Dashboard / Vulnerabilities / CLSA-2023-1681491348
CLSA-2023-1681491348
Summary: Fix CVE(s): CVE-2023-27536, CVE-2023-27535, CVE-2023-27533
Details: * SECURITY UPDATE: Telnet option IAC injection - debian/patches/CVE-2023-27533.patch: only accept option arguments in ascii to avoid embedded telnet negotiation commands - CVE-2023-27533 * SECURITY UPDATE: FTP too eager connection reuse - debian/patches/CVE-2023-27535.patch: add more conditions for connection reuse - CVE-2023-27535 * SECURITY UPDATE: GSS delegation too eager connection re-use - debian/patches/CVE-2023-27536.patch: only reuse connections with same GSS delegation - CVE-2023-27536
Affected packages
Package
Name: curl
Purl: pkg:deb/tuxcare/curl?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
