A heap-based buffer overflow flaw in the SOCKS5 proxy handshake of the Curl package that could lead to arbitrary remote code execution when using SOCKS5 proxies to access untrusted web servers.
It is a low severity vulnerability that only impacts libcurl – a library provided by the Curl project that allows developers to access Curl APIs from their own code.
ARD Hub 3.3 and older
This is a third-party vulnerability.
CVE-2023-38545 (SOCKS5 heap buffer overflow):
CVE-2023-38546 (Cookie injection with none file):
ARD Studio and ARD Hub are not impacted by this since we do not have this component in our images.
This has been is completely addressed in ARD Hub 3.4. Broadcom highly recommends upgrading to the latest version once it is available.
This KB will be updated on a continuous basis as the situation evolves.