Debian DSA-5460-1 : curl - security update (deprecated)

critical Nessus Plugin ID 178917

Synopsis

This plugin has been deprecated.

Description

This plugin has been deprecated as the CVE that is assessed by the plugin has been rejected.

See Also

https://security-tracker.debian.org/tracker/source-package/curl

https://www.debian.org/security/2023/dsa-5460

https://security-tracker.debian.org/tracker/CVE-2023-32001

https://packages.debian.org/source/bookworm/curl

Plugin Details

Severity: Critical

ID: 178917

File Name: debian_DSA-5460.nasl

Version: 1.4

Type: local

Agent: unix

Published: 7/27/2023

Updated: 8/31/2023

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2023-32001

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:libcurl4, p-cpe:/a:debian:debian_linux:curl, cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:libcurl3-nss, p-cpe:/a:debian:debian_linux:libcurl4-gnutls-dev, p-cpe:/a:debian:debian_linux:libcurl4-doc, p-cpe:/a:debian:debian_linux:libcurl3-gnutls, p-cpe:/a:debian:debian_linux:libcurl4-nss-dev, p-cpe:/a:debian:debian_linux:libcurl4-openssl-dev

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/26/2023

Vulnerability Publication Date: 7/20/2023

Reference Information

CVE: CVE-2023-32001