VDB
BDU%3A2024-06023
BDU%3A2024-06023
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость функции utf8asn1str() парсера ASN1 утилиты командной строки cURL, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp, ООО «Ред Софт», ООО «РусБИТех-Астра», АО «ИВК», Daniel Stenberg, ООО «Открытая мобильная платформа» | Windows 10 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), РЕД ОС (запись в едином реестре российских программ №3751), Windows 10 21H2, Astra Linux Special Edition (запись в едином реестре российских программ №369), Альт 8 СП (запись в едином реестре российских программ №4305), Windows 11 22H2, Windows 10 22H2, Windows 11 21H2, АЛЬТ СП 10, Windows 11 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), cURL, Windows 11 24H2, CBL Mariner, ОС Аврора (запись в едином реестре российских программ №1543) |
Timeline
- Aug 7, 2024 CVE Published
- Jan 31, 2025 CVE Updated
- Mar 19, 2026 Security Advisory
References
- http://www.openwall.com/lists/oss-security/2024/07/24/1 url
- http://www.openwall.com/lists/oss-security/2024/07/24/5 url
- https://curl.se/docs/CVE-2024-6197.json url
- https://hackerone.com/reports/2559516 url
- https://github.com/curl/curl/commit/3a537a4db9e65e545 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2024-0830SE17 url
- https://curl.se/docs/CVE-2024-6197.html advisory
- https://github.com/curl/curl/commit/3a537a4db9e65e545ec45b1b5d5575ee09a2569d advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-6197 advisory
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2024-1031SE47 advisory
- https://altsp.su/obnovleniya-bezopasnosti/ advisory
- https://cve.omp.ru/bb25402 advisory