CVE-2023-32001

CVE-2023-32001

libcurl can be told to save cookie, HSTS and/or alt-svc data to files. When
doing this, it called `stat()` followed by `fopen()` in a way that made it
vulnerable to a TOCTOU race condition problem.

By exploiting this flaw, an attacker could trick the victim to create or
overwrite protected files holding this data in ways it was not intended to.

Source: CVE-2023-32001

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다