OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 23.7 Legacy Series »
  • 23.7.6 update curl-8.3.0 is vulnerable
« previous next »
  • Print
Pages: [1]

Author Topic: 23.7.6 update curl-8.3.0 is vulnerable  (Read 1947 times)

gdur

  • Full Member
  • ***
  • Posts: 124
  • Karma: 2
    • View Profile
23.7.6 update curl-8.3.0 is vulnerable
« on: October 14, 2023, 11:26:25 am »
Just upgraded from 23.7.5 to 23.7.6 and found this after a security audit:
Quote
***GOT REQUEST TO AUDIT SECURITY***
Currently running OPNsense 23.7.6 at Sat Oct 14 11:19:49 CEST 2023
vulnxml file up-to-date
curl-8.3.0 is vulnerable:
  curl -- SOCKS5 heap buffer overflow
  CVE: CVE-2023-38545
  WWW: https://vuxml.FreeBSD.org/freebsd/d6c19e8c-6806-11ee-9464-b42e991fc52e.html

1 problem(s) in 1 installed package(s) found.
***DONE***
In curl-8.4.0 it has been fixed...
Logged

meyergru

  • Hero Member
  • *****
  • Posts: 1769
  • Karma: 172
  • IT Aficionado
    • View Profile
    • congenio
Re: 23.7.6 update curl-8.3.0 is vulnerable
« Reply #1 on: October 14, 2023, 12:33:14 pm »
Do you use curl with a SOCKS5 proxy? No? Good.
Logged
Intel N100, 4 x I226-V, 16 GByte, 256 GByte NVME, ZTE F6005

1100 down / 440 up, Bufferbloat A+

CJ

  • Hero Member
  • *****
  • Posts: 832
  • Karma: 30
    • View Profile
    • Have Answer, Will Blog
Re: 23.7.6 update curl-8.3.0 is vulnerable
« Reply #2 on: October 14, 2023, 03:17:29 pm »
The OPNSense team are good at updating things like this.  IIRC, last time there was a patch release for it.  Give it some time.
Logged
Have Answer, Will Blog

misterjaytee

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
Re: 23.7.6 update curl-8.3.0 is vulnerable
« Reply #3 on: October 14, 2023, 04:44:49 pm »
This issue also exists in 23.7.5, it's not specific to 23.7.6. In fact, looking at the versions of curl that this affects, it would have been an issue going back at least 3 years (and not just for OPNsense, but for any device that uses curl/libcurl).

Whilst it is a high severity vulnerability, it should only be an issue if you use a socks5 proxy - there are also some recommendations at the bottom of this page:
https://curl.se/docs/CVE-2023-38545.html
Logged

misterjaytee

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
Re: 23.7.6 update curl-8.3.0 is vulnerable
« Reply #4 on: October 27, 2023, 04:25:10 pm »
This has been fixed in 23.7.7:
ports: curl 8.4.0

Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17745
  • Karma: 1620
    • View Profile
Re: 23.7.6 update curl-8.3.0 is vulnerable
« Reply #5 on: October 27, 2023, 04:32:46 pm »
In a surprising twist the last update picked up the required security update. ;)


Cheers,
Franco
Logged

misterjaytee

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
Re: 23.7.6 update curl-8.3.0 is vulnerable
« Reply #6 on: October 28, 2023, 02:21:51 pm »
Quote from: franco on October 27, 2023, 04:32:46 pm
In a surprising twist the last update picked up the required security update. ;)


Cheers,
Franco

Let's hope the next update has a surprising twist and fixes the multiple squid vulnerabilities  ;) :

squid-5.9 is vulnerable:
  squid -- Multiple vulnerabilities
  WWW: https://vuxml.FreeBSD.org/freebsd/a8fb8e3a-730d-11ee-ab61-b42e991fc52e.html
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17745
  • Karma: 1620
    • View Profile
Re: 23.7.6 update curl-8.3.0 is vulnerable
« Reply #7 on: October 31, 2023, 03:36:22 pm »
Spoiler: tested squid 6.4 and it's queued up for 23.7.8.


Cheers,
Franco
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 23.7 Legacy Series »
  • 23.7.6 update curl-8.3.0 is vulnerable
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2