V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2023-38039
DEB
HighConfirmedExploit available

When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. Howeve…

CVSS
7.5
High
EPSS
0.15
p94
Published
2023-01-01
Updated
2023-01-01
Description

When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

Tags · CWE
Pre-auth
CWE-400
CWE-770
CAPEC-125
CAPEC-130
CAPEC-147
CAPEC-197
CAPEC-227
CAPEC-229
CAPEC-230
CAPEC-231
CAPEC-469
CAPEC-482
CAPEC-486
CAPEC-487
CAPEC-488
CAPEC-489
CAPEC-490
CAPEC-491
CAPEC-492
CAPEC-493
CAPEC-494
CAPEC-495
CAPEC-496
CAPEC-528
Affected products
Curl 7.84.0–8.3.0
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.148 · p94
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-125 · CWE-770
└ via CAPEC-490 · CWE-770
└ via CAPEC-125 · CWE-770
└ via CAPEC-482 · CWE-770
└ via CAPEC-469 · CWE-770
└ via CAPEC-130 · CWE-770
Known exploits — Сканер-ВС
CVE-2023-38039
github-poc · https://github.com/Smartkeyss/CVE-2023-38039
Enterprise
Affected software
ProductVendorStatus
curlTracked
curlTracked
curlTracked
curlTracked
curlTracked
curlTracked
curlTracked
curlTracked
curlTracked
curlTracked
curlTracked
curlTracked
curlTracked
jbcs-httpd24-curlTracked
jbcs-httpd24-curlTracked
libcurlTracked
libcurl-develTracked
curl*Tracked
fedora*Tracked
windows_10_1809*Tracked
Source databases
DEB
MSR
CVE
RED
UBU
Related vulnerabilities