imPC@ndo IT

Tracker / CVE-2023-38039

CVE-2023-38039

High 7.5

When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

Affected products and versions

fedoraproject fedora
haxx curl · 7.84.0 → 8.3.0
microsoft windows_10_1809 · … → 10.0.17763.5122
microsoft windows_10_21h2 · … → 10.0.19044.3693
microsoft windows_10_22h2 · … → 10.0.19045.3693
microsoft windows_11_21h2 · … → 10.0.22000.2600
microsoft windows_11_22h2 · … → 10.0.22621.2715
microsoft windows_11_23h2 · … → 10.0.22631.2715
microsoft windows_server_2019 · … → 10.0.17763.5122
microsoft windows_server_2022 · … → 10.0.20348.2113

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References