Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3398-1 | curl security update |
EUVD |
EUVD-2023-31291 | An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed. |
Ubuntu USN |
USN-5964-1 | curl vulnerabilities |
Ubuntu USN |
USN-5964-2 | curl vulnerabilities |
Fri, 14 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-02-14T15:39:25.676Z
Reserved: 2023-03-02T00:00:00.000Z
Link: CVE-2023-27536
Updated: 2024-08-02T12:16:35.616Z
Status : Modified
Published: 2023-03-30T20:15:07.547
Modified: 2025-02-14T16:15:33.497
Link: CVE-2023-27536
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN