Data Protection Advisor가 libcurl 7.9.1 8.4.0 쿠키 삽입의 영향을 받습니까?

Summary: libcurl 7.9.1 8.4.0 쿠키 삽입이 DPA(Data Protection Advisor)에 영향을 줍니까?

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

보안 스캐너가 DPA 에이전트에 대해 "libcurl 7.9.1 8.4.0 쿠키 삽입" 을 보고합니다.

영향을 받는 경로:
/opt/emc/dpa/agent/lib/libcurl.so.4
설치된 버전:
  • 7.47.1
수정된 버전:
  • 8.4.0

Cause

이 취약점은 API 사용으로 인해 발생합니다.
"curl_easy_duphandle".
이 취약성은 CVE-2023-38546에 설명되어 있습니다.
파일이 없는 쿠키 삽입
  이 하이퍼링크는 Dell Technologies 외부의 웹사이트로 연결됩니다.

Resolution

DPA 엔지니어링에 따라 DPA 에이전트 서비스 및 DPA는 이 API를 사용하지 않습니다. 이 취약성은 DPA 또는 DPA 에이전트 서비스에 영향을 주지 않습니다. 작업이 필요하지 않습니다. 

Affected Products

Data Protection Advisor
Article Properties
Article Number: 000221431
Article Type: Solution
Last Modified: 01 Feb 2024
Version:  2
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.