Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-28320


A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave.


Published

2023-05-26T21:15:15.937

Last Modified

2025-01-15T16:15:25.953

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-400
  • Type: Primary
    CWE-362
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application haxx curl < 8.1.0 Yes
Operating System apple macos < 11.7.9 Yes
Operating System apple macos < 12.6.8 Yes
Operating System apple macos < 13.5 Yes
Application netapp clustered_data_ontap - Yes
Application netapp ontap_antivirus_connector - Yes
Operating System netapp h300s_firmware - Yes
Hardware netapp h300s - No
Operating System netapp h500s_firmware - Yes
Hardware netapp h500s - No
Operating System netapp h700s_firmware - Yes
Hardware netapp h700s - No
Operating System netapp h410s_firmware - Yes
Hardware netapp h410s - No

References