ALAS-2024-606


Amazon Linux 2023 Security Advisory: ALAS-2024-606
Advisory Release Date: 2024-04-25 16:40 Pacific
Advisory Updated Date: 2024-04-25 16:40 Pacific
Severity: Medium

Issue Overview:

This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains.

It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with domain=co.UK when the URL used a lowercase hostname curl.co.uk, even though co.uk is listed as a PSL domain. (CVE-2023-46218)


Affected Packages:

curl


Issue Correction:
Run dnf update curl --releasever 2023.4.20240429 to update your system.

New Packages:
aarch64:
    curl-minimal-debuginfo-8.5.0-1.amzn2023.0.2.aarch64
    libcurl-debuginfo-8.5.0-1.amzn2023.0.2.aarch64
    libcurl-8.5.0-1.amzn2023.0.2.aarch64
    curl-debugsource-8.5.0-1.amzn2023.0.2.aarch64
    libcurl-minimal-debuginfo-8.5.0-1.amzn2023.0.2.aarch64
    curl-8.5.0-1.amzn2023.0.2.aarch64
    libcurl-minimal-8.5.0-1.amzn2023.0.2.aarch64
    curl-debuginfo-8.5.0-1.amzn2023.0.2.aarch64
    curl-minimal-8.5.0-1.amzn2023.0.2.aarch64
    libcurl-devel-8.5.0-1.amzn2023.0.2.aarch64

src:
    curl-8.5.0-1.amzn2023.0.2.src

x86_64:
    libcurl-debuginfo-8.5.0-1.amzn2023.0.2.x86_64
    curl-minimal-debuginfo-8.5.0-1.amzn2023.0.2.x86_64
    libcurl-minimal-8.5.0-1.amzn2023.0.2.x86_64
    curl-debugsource-8.5.0-1.amzn2023.0.2.x86_64
    curl-debuginfo-8.5.0-1.amzn2023.0.2.x86_64
    libcurl-minimal-debuginfo-8.5.0-1.amzn2023.0.2.x86_64
    curl-8.5.0-1.amzn2023.0.2.x86_64
    curl-minimal-8.5.0-1.amzn2023.0.2.x86_64
    libcurl-8.5.0-1.amzn2023.0.2.x86_64
    libcurl-devel-8.5.0-1.amzn2023.0.2.x86_64