Asymmetric denial of service In curl
Description
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using alarm() and siglongjmp(). When doing this, libcurl used a global buffer that was not mutex protected and a multi-threaded application might therefore crash or otherwise misbehave.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.18 | 8.1.0-r0 | ||
alpine v3.21 | 8.1.0-r0 | ||
alpine v3.15 | 8.1.0-r0 | ||
debian 12 | 7.88.1-10 | ||
alpine v3.17 | 8.1.0-r0 | ||
alpine v3.19 | 8.1.0-r0 | ||
alpine v3.16 | 8.1.0-r0 | ||
alpine v3.20 | 8.1.0-r0 | ||
alpine v3.22 | 8.1.0-r0 | ||
debian 13 | 7.88.1-10 |
1-10 of 14
10
Aliases
1. 2. 3. 4. 5. 6. 7.