ALAS2-2023-2271

Related Vulnerabilities: CVE-2023-38039  

HTTP headers eat all memory NOTE: https://www.openwall.com/lists/oss-security/2023/09/13/1NOTE: https://curl.se/docs/CVE-2023-38039.htmlNOTE: Introduced by: https://github.com/curl/curl/commit/7c8c723682d524ac9580b9ca3b71419163cb5660 (curl-7_83_0)NOTE: Experimental tag removed in: https://github.com/curl/curl/commit/4d94fac9f0d1dd02b8308291e4c47651142dc28b (curl-7_84_0)NOTE: Fixed by: https://github.com/curl/curl/commit/3ee79c1674fd6f99e8efca52cd7510e08b766770 (curl-8_3_0) (CVE-2023-38039)

ALAS2-2023-2271


Amazon Linux 2 Security Advisory: ALAS-2023-2271
Advisory Release Date: 2023-09-27 22:48 Pacific
Advisory Updated Date: 2023-10-05 22:03 Pacific
Severity: Important

Issue Overview:

HTTP headers eat all memory

NOTE: https://www.openwall.com/lists/oss-security/2023/09/13/1
NOTE: https://curl.se/docs/CVE-2023-38039.html
NOTE: Introduced by: https://github.com/curl/curl/commit/7c8c723682d524ac9580b9ca3b71419163cb5660 (curl-7_83_0)
NOTE: Experimental tag removed in: https://github.com/curl/curl/commit/4d94fac9f0d1dd02b8308291e4c47651142dc28b (curl-7_84_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/3ee79c1674fd6f99e8efca52cd7510e08b766770 (curl-8_3_0) (CVE-2023-38039)


Affected Packages:

curl


Issue Correction:
Run yum update curl to update your system.

New Packages:
aarch64:
    curl-8.3.0-1.amzn2.0.1.aarch64
    libcurl-8.3.0-1.amzn2.0.1.aarch64
    libcurl-devel-8.3.0-1.amzn2.0.1.aarch64
    curl-debuginfo-8.3.0-1.amzn2.0.1.aarch64

i686:
    curl-8.3.0-1.amzn2.0.1.i686
    libcurl-8.3.0-1.amzn2.0.1.i686
    libcurl-devel-8.3.0-1.amzn2.0.1.i686
    curl-debuginfo-8.3.0-1.amzn2.0.1.i686

src:
    curl-8.3.0-1.amzn2.0.1.src

x86_64:
    curl-8.3.0-1.amzn2.0.1.x86_64
    libcurl-8.3.0-1.amzn2.0.1.x86_64
    libcurl-devel-8.3.0-1.amzn2.0.1.x86_64
    curl-debuginfo-8.3.0-1.amzn2.0.1.x86_64