Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 894676 (CVE-2023-23914, CVE-2023-23915, CVE-2023-23916)

Summary: <net-misc/curl-7.88.0: Multiple vulnerabilities
Product: Gentoo Security Reporter: Matt Jolly <kangie>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: base-system, kangie
Priority: Normal Keywords: PullRequest
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://curl.se/docs/vuln-7.87.0.html
See Also: https://github.com/gentoo/gentoo/pull/29607
Whiteboard: A3 [glsa+]
Package list:
Runtime testing required: ---

Description Matt Jolly gentoo-dev 2023-02-16 05:36:07 UTC
Multiple CVEs in cURL <7.88.0

Reproducible: Always
Comment 1 Matt Jolly gentoo-dev 2023-02-16 05:46:19 UTC
See (though there's not much info):

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23914 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23915 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23916

cURL 7.88.0 is currently masked due to HTTP/2 issues. I'll keep an eye on upstream and either apply patches to unmask or bump the package if there's a new release.
Comment 2 Larry the Git Cow gentoo-dev 2023-02-17 05:13:58 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=04f8286d4a957947b08a02402a6ca6c8f949e26e

commit 04f8286d4a957947b08a02402a6ca6c8f949e26e
Author:     Matt Jolly <Matt.Jolly@footclan.ninja>
AuthorDate: 2023-02-16 10:14:47 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-02-17 05:09:07 +0000

    net-misc/curl: add 7.88.0-r1
    
    * Add HTTP/2 patchset
    * Add test fix patchset
    
    Bug: https://bugs.gentoo.org/894676
    Signed-off-by: Matt Jolly <Matt.Jolly@footclan.ninja>
    Signed-off-by: Sam James <sam@gentoo.org>

 net-misc/curl/curl-7.88.0-r1.ebuild         | 298 ++++++++++++++++++++++++++++
 net-misc/curl/files/curl-7.88.0-http2.patch |  93 +++++++++
 net-misc/curl/files/curl-7.88.0-tests.patch | 120 +++++++++++
 3 files changed, 511 insertions(+)
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-02-20 20:44:56 UTC
Thanks!
Comment 4 Larry the Git Cow gentoo-dev 2023-10-11 08:41:29 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=3dfe02046c2bc76fb7e910a04702603b72fcb98c

commit 3dfe02046c2bc76fb7e910a04702603b72fcb98c
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2023-10-11 08:40:59 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-10-11 08:41:24 +0000

    [ GLSA 202310-12 ] curl: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/887745
    Bug: https://bugs.gentoo.org/894676
    Bug: https://bugs.gentoo.org/902801
    Bug: https://bugs.gentoo.org/906590
    Bug: https://bugs.gentoo.org/910564
    Bug: https://bugs.gentoo.org/914091
    Bug: https://bugs.gentoo.org/915195
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Sam James <sam@gentoo.org>

 glsa-202310-12.xml | 68 ++++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 68 insertions(+)