Vulnerability Description
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Haxx | Libcurl | 7.88.0 |
| Netapp | Active Iq Unified Manager | - |
| Netapp | Clustered Data Ontap | 9.0 |
| Broadcom | Brocade Fabric Operating System Firmware | - |
| Netapp | H300S Firmware | - |
| Netapp | H300S | - |
| Netapp | H500S Firmware | - |
| Netapp | H500S | - |
| Netapp | H700S Firmware | - |
| Netapp | H700S | - |
| Netapp | H410S Firmware | - |
| Netapp | H410S | - |
| Splunk | Universal Forwarder | >= 8.2.0, < 8.2.12 |
Related Weaknesses (CWE)
References
- https://hackerone.com/reports/1897203ExploitThird Party Advisory
- https://security.gentoo.org/glsa/202310-12Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230420-0010/Third Party Advisory
- https://hackerone.com/reports/1897203ExploitThird Party Advisory
- https://security.gentoo.org/glsa/202310-12Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230420-0010/Third Party Advisory
FAQ
What is CVE-2023-27537?
CVE-2023-27537 is a vulnerability with a CVSS score of 5.9 (MEDIUM). A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads b...
How severe is CVE-2023-27537?
CVE-2023-27537 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-27537?
Check the references section above for vendor advisories and patch information. Affected products include: Haxx Libcurl, Netapp Active Iq Unified Manager, Netapp Clustered Data Ontap, Broadcom Brocade Fabric Operating System Firmware, Netapp H300S Firmware.