Security Fix(es):
A vulnerability was found in curl. This issue occurs because it mishandles message verification failures when curl does FTP transfers secured by krb5. This flaw makes it possible for a Man-in-the-middle attack to go unnoticed and allows data injection into the client.(CVE-2022-32208)
A vulnerability was found in curl. This issue occurs because the number of acceptable "links" in the "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps. This flaw leads to a denial of service, either by mistake or by a malicious actor.(CVE-2022-32206)
A vulnerability was found in curl. This issue occurs because when curl saves cookies, alt-svc, and HSTS data to local files, it makes the operation atomic by finalizing the process with a rename from a temporary name to the final target file name. This flaw leads to unpreserved file permissions, either by mistake or by a malicious actor.(CVE-2022-32207)
A vulnerability was found in curl. This issue occurs because a malicious server can serve excessive amounts of Set-Cookie:
headers in an HTTP response to curl, which stores all of them. This flaw leads to a denial of service, either by mistake or by a malicious actor.(CVE-2022-32205)
{ "severity": "Medium" }
{ "src": [ "curl-7.71.1-15.oe1.src.rpm" ], "x86_64": [ "libcurl-devel-7.71.1-15.oe1.x86_64.rpm", "curl-7.71.1-15.oe1.x86_64.rpm", "curl-debuginfo-7.71.1-15.oe1.x86_64.rpm", "curl-debugsource-7.71.1-15.oe1.x86_64.rpm", "libcurl-7.71.1-15.oe1.x86_64.rpm" ], "aarch64": [ "curl-debugsource-7.71.1-15.oe1.aarch64.rpm", "curl-debuginfo-7.71.1-15.oe1.aarch64.rpm", "libcurl-devel-7.71.1-15.oe1.aarch64.rpm", "libcurl-7.71.1-15.oe1.aarch64.rpm", "curl-7.71.1-15.oe1.aarch64.rpm" ], "noarch": [ "curl-help-7.71.1-15.oe1.noarch.rpm" ] }
{ "src": [ "curl-7.71.1-15.oe1.src.rpm" ], "x86_64": [ "curl-7.71.1-15.oe1.x86_64.rpm", "libcurl-devel-7.71.1-15.oe1.x86_64.rpm", "curl-debuginfo-7.71.1-15.oe1.x86_64.rpm", "curl-debugsource-7.71.1-15.oe1.x86_64.rpm", "libcurl-7.71.1-15.oe1.x86_64.rpm" ], "aarch64": [ "curl-debuginfo-7.71.1-15.oe1.aarch64.rpm", "libcurl-devel-7.71.1-15.oe1.aarch64.rpm", "curl-7.71.1-15.oe1.aarch64.rpm", "libcurl-7.71.1-15.oe1.aarch64.rpm", "curl-debugsource-7.71.1-15.oe1.aarch64.rpm" ], "noarch": [ "curl-help-7.71.1-15.oe1.noarch.rpm" ] }
{ "src": [ "curl-7.79.1-7.oe2203.src.rpm" ], "x86_64": [ "curl-debugsource-7.79.1-7.oe2203.x86_64.rpm", "libcurl-devel-7.79.1-7.oe2203.x86_64.rpm", "curl-debuginfo-7.79.1-7.oe2203.x86_64.rpm", "curl-7.79.1-7.oe2203.x86_64.rpm", "libcurl-7.79.1-7.oe2203.x86_64.rpm" ], "aarch64": [ "curl-7.79.1-7.oe2203.aarch64.rpm", "curl-debuginfo-7.79.1-7.oe2203.aarch64.rpm", "libcurl-7.79.1-7.oe2203.aarch64.rpm", "curl-debugsource-7.79.1-7.oe2203.aarch64.rpm", "libcurl-devel-7.79.1-7.oe2203.aarch64.rpm" ], "noarch": [ "curl-help-7.79.1-7.oe2203.noarch.rpm" ] }