Logo
vulnerabilityCVE-2023-46219
Name
CVE-2023-46219
Source
NVD ( link)Debian ( link)
Description
When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
curl
Patched

Vulnerability Ratings#


5.3
CVSSv31
5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
8.20.0
Not Affected
buildroot
master
8.21.0
Not Affected
openwrt
master
8.19.0-r2
Not Affected
openwrt
master
8.20.0-r1
Not Affected
openwrt
openwrt-25.12
8.19.0-r2
Not Affected
openwrt
openwrt-25.12
8.14.1-r1
Not Affected
yocto
master
8.20.0
Not Affected
yocto
scarthgap
8.7.1
Not Affected

Resolved with patches#


curl (yocto:kirkstone)

#
Title
Author
Resolve
1
fopen: allocate the dir after fopen
Daniel Stenberg <daniel@haxx.se>
CVE-2023-46219
2
fopen: create short(er) temporary file name
Daniel Stenberg <daniel@haxx.se>
CVE-2023-46219
3
fopen: optimize
SaltyMilk <soufiane.elmelcaoui@gmail.com>
CVE-2023-46219