ALAS2023-2023-368


Amazon Linux 2023 Security Advisory: ALAS-2023-368
Advisory Release Date: 2023-09-27 21:06 Pacific
Advisory Updated Date: 2023-10-03 20:50 Pacific
Severity: Important

Issue Overview:

HTTP headers eat all memory

NOTE: https://www.openwall.com/lists/oss-security/2023/09/13/1
NOTE: https://curl.se/docs/CVE-2023-38039.html
NOTE: Introduced by: https://github.com/curl/curl/commit/7c8c723682d524ac9580b9ca3b71419163cb5660 (curl-7_83_0)
NOTE: Experimental tag removed in: https://github.com/curl/curl/commit/4d94fac9f0d1dd02b8308291e4c47651142dc28b (curl-7_84_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/3ee79c1674fd6f99e8efca52cd7510e08b766770 (curl-8_3_0) (CVE-2023-38039)


Affected Packages:

curl


Issue Correction:
Run dnf update curl --releasever 2023.2.20231002 to update your system.

New Packages:
aarch64:
    libcurl-debuginfo-8.3.0-1.amzn2023.0.1.aarch64
    libcurl-minimal-debuginfo-8.3.0-1.amzn2023.0.1.aarch64
    curl-8.3.0-1.amzn2023.0.1.aarch64
    curl-minimal-8.3.0-1.amzn2023.0.1.aarch64
    curl-debuginfo-8.3.0-1.amzn2023.0.1.aarch64
    curl-minimal-debuginfo-8.3.0-1.amzn2023.0.1.aarch64
    curl-debugsource-8.3.0-1.amzn2023.0.1.aarch64
    libcurl-minimal-8.3.0-1.amzn2023.0.1.aarch64
    libcurl-8.3.0-1.amzn2023.0.1.aarch64
    libcurl-devel-8.3.0-1.amzn2023.0.1.aarch64

src:
    curl-8.3.0-1.amzn2023.0.1.src

x86_64:
    curl-minimal-debuginfo-8.3.0-1.amzn2023.0.1.x86_64
    curl-debuginfo-8.3.0-1.amzn2023.0.1.x86_64
    libcurl-minimal-8.3.0-1.amzn2023.0.1.x86_64
    curl-minimal-8.3.0-1.amzn2023.0.1.x86_64
    curl-debugsource-8.3.0-1.amzn2023.0.1.x86_64
    libcurl-debuginfo-8.3.0-1.amzn2023.0.1.x86_64
    curl-8.3.0-1.amzn2023.0.1.x86_64
    libcurl-minimal-debuginfo-8.3.0-1.amzn2023.0.1.x86_64
    libcurl-8.3.0-1.amzn2023.0.1.x86_64
    libcurl-devel-8.3.0-1.amzn2023.0.1.x86_64