CVE-2023-38546

3.7 LOW
Published: October 18, 2023 Modified: November 04, 2025

Description

This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application creates "easy handles" that are the individual handles for single transfers. libcurl provides a function call that duplicates en easy handle called [curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html). If a transfer has cookies enabled when the handle is duplicated, the cookie-enable state is also cloned - but without cloning the actual cookies. If the source handle did not read any cookies from a specific file on disk, the cloned version of the handle would instead store the file name as `none` (using the four ASCII letters, no quotes). Subsequent use of the cloned handle that does not explicitly set a source to load cookies from would then inadvertently load cookies from a file named `none` - if such a file exists and is readable in the current directory of the program using libcurl. And if using the correct file format of course.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://curl.se/docs/CVE-2023-38546.html
Source: support@hackerone.com
Patch Third Party Advisory
https://support.apple.com/kb/HT214036
Source: support@hackerone.com
https://support.apple.com/kb/HT214057
Source: support@hackerone.com
https://support.apple.com/kb/HT214058
Source: support@hackerone.com
https://support.apple.com/kb/HT214063
Source: support@hackerone.com
http://seclists.org/fulldisclosure/2024/Jan/34
Source: af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2024/Jan/37
Source: af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2024/Jan/38
Source: af854a3a-2127-422b-91ae-364da2661108
https://curl.se/docs/CVE-2023-38546.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory
https://forum.vmssoftware.com/viewtopic.php?f=8&t=8868
Source: af854a3a-2127-422b-91ae-364da2661108
https://support.apple.com/kb/HT214036
Source: af854a3a-2127-422b-91ae-364da2661108
https://support.apple.com/kb/HT214057
Source: af854a3a-2127-422b-91ae-364da2661108
https://support.apple.com/kb/HT214058
Source: af854a3a-2127-422b-91ae-364da2661108
https://support.apple.com/kb/HT214063
Source: af854a3a-2127-422b-91ae-364da2661108

21 reference(s) from NVD

Quick Stats

CVSS v3 Score
3.7 / 10.0
EPSS (Exploit Probability)
0.2%
46th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

haxx