{"id":"USN-6237-2","summary":"curl regression","details":"USN-6237-1 fixed vulnerabilities in curl. The update caused a certificate\nwildcard handling regression on Ubuntu 22.04 LTS. This update fixes the\nproblem.\n\nWe apologize for the inconvenience.\n\nOriginal advisory details:\n\n Hiroki Kurosawa discovered that curl incorrectly handled validating certain\n certificate wildcards. A remote attacker could possibly use this issue to\n spoof certain website certificates using IDN hosts. (CVE-2023-28321)\n \n Hiroki Kurosawa discovered that curl incorrectly handled callbacks when\n certain options are set by applications. This could cause applications\n using curl to misbehave, resulting in information disclosure, or a denial\n of service. (CVE-2023-28322)\n \n It was discovered that curl incorrectly handled saving cookies to files. A\n local attacker could possibly use this issue to create or overwrite files.\n This issue only affected Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-32001)\n","modified":"2026-04-22T10:37:35.011141Z","published":"2023-07-19T17:34:44Z","references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6237-2"},{"type":"REPORT","url":"https://launchpad.net/bugs/2028170"}],"affected":[{"package":{"name":"curl","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/curl@7.81.0-1ubuntu1.13?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.81.0-1ubuntu1.13"}]}],"versions":["7.74.0-1.3ubuntu2","7.74.0-1.3ubuntu3","7.80.0-3","7.81.0-1","7.81.0-1ubuntu1.1","7.81.0-1ubuntu1.2","7.81.0-1ubuntu1.3","7.81.0-1ubuntu1.4","7.81.0-1ubuntu1.6","7.81.0-1ubuntu1.7","7.81.0-1ubuntu1.8","7.81.0-1ubuntu1.10","7.81.0-1ubuntu1.11"],"ecosystem_specific":{"binaries":[{"binary_version":"7.81.0-1ubuntu1.13","binary_name":"curl"},{"binary_version":"7.81.0-1ubuntu1.13","binary_name":"libcurl3-gnutls"},{"binary_version":"7.81.0-1ubuntu1.13","binary_name":"libcurl3-nss"},{"binary_version":"7.81.0-1ubuntu1.13","binary_name":"libcurl4"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6237-2.json","cves_map":{"cves":[],"ecosystem":"Ubuntu:22.04:LTS"}}}],"schema_version":"1.7.5"}