CVE-2023-28320
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave.
- Haxx Curl
- < 8.1.0
- Fix
- Available
- CVSS 3.1
- 5.9 MEDIUM
- EPSS
- 2.7% (84th percentile)
- Weakness
- CWE-400, CWE-362
- NVD status
- Modified
- Published
- 2023-05-26
CVE-2023-28320 at NVD
No indexed exploits for CVE-2023-28320 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-28320 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.