Sploitus

CVE-2023-28320

No indexed exploits for CVE-2023-28320 yet

A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave.

Affected products
Alt Linux, Debian, Apple Macos, Red Os, Suse, Curl
Haxx Curl
< 8.1.0
Fix
Available
CVSS 3.1
5.9 MEDIUM
EPSS
2.7% (84th percentile)
Weakness
CWE-400, CWE-362
NVD status
Modified
Published
2023-05-26
CVE-2023-28320 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-28320 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-28320 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.