Curl 7.84 <= 8.2.1 Header DoS (CVE-2023-38039)

TK 300 Reputation points
2023-09-18T15:20:35.8933333+00:00

Tenable scanners are now detecting "Curl 7.84 <= 8.2.1 Header DoS (CVE-2023-38039)" on some of our Windows Server 2022 servers. (https://www.tenable.com/plugins/nessus/181409). The stated solution is "Upgrade Curl to version 8.3.0 or later".

Will Microsoft be addressing this issue when the October updates are released on October 10, 2023?

Windows for business | Windows Server | User experience | Other
{count} votes

4 answers

Sort by: Most helpful
  1. LilHammer 30 Reputation points
    2023-10-12T16:46:04.95+00:00

    This needs to be escalated for a response from Microsoft corporate... It is 100% unacceptable and indefensible for Microsoft to incorporate open-source code in a way that requires only Microsoft packaged updates and fixes, when Microsoft has no intention of maintaining the code they decided to incorporate! This is another example of Microsoft doing things the programming community doesn't want while ensuring Windows is more vulnerable than ever before.

    If Microsoft won't meet industry-standard patching deadlines, STOP INCORPORATING MORE OPEN SOURCE CODE into the OS but REQUIRING MS PACKAGED FIXES!

    This is exactly like the old Macromedia Flash problem. STOP IT.

    6 people found this answer helpful.

  2. Siddharth Sharma 6 Reputation points
    2023-09-26T15:33:15.06+00:00

    Same here, most of Windows 10 machines are reporting this on Nessus.

    I hope this is fixed in next update from MS .

    1 person found this answer helpful.

  3. Josh Nielsen 0 Reputation points
    2023-09-21T20:30:49.6133333+00:00

    I second this question. This impacts Windows 10 as well.


  4. Buckingham, Nicholas S 0 Reputation points
    2023-10-31T15:48:48.95+00:00
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.