Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Bug#1031371: curl: CVE-2023-23914 CVE-2023-23915 CVE-2023-23916

35 views
Skip to first unread message

Moritz Mühlenhoff

unread,
Feb 15, 2023, 5:30:05 PM2/15/23
to
Source: curl
X-Debbugs-CC: te...@security.debian.org
Severity: grave
Tags: security

Hi,

The following vulnerabilities were published for curl.

CVE-2023-23914
curl: HSTS ignored on multiple requests
https://curl.se/docs/CVE-2023-23916.html

CVE-2023-23915
curl: HSTS amnesia with --parallel
https://curl.se/docs/CVE-2023-23915.html

CVE-2023-23914
curl: HSTS ignored on multiple requests
https://curl.se/docs/CVE-2023-23914.html


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-23914
https://www.cve.org/CVERecord?id=CVE-2023-23914
[1] https://security-tracker.debian.org/tracker/CVE-2023-23915
https://www.cve.org/CVERecord?id=CVE-2023-23915
[2] https://security-tracker.debian.org/tracker/CVE-2023-23916
https://www.cve.org/CVERecord?id=CVE-2023-23916

Please adjust the affected versions in the BTS as needed.
0 new messages