UBUNTU-CVE-2022-43552

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2022-43552
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-43552.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2022-43552
Related
Published
2022-12-21T00:00:00Z
Modified
2022-12-21T00:00:00Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to tunnel virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

References

Affected packages

Ubuntu:Pro:14.04:LTS / curl

Package

Name
curl
Purl
pkg:deb/ubuntu/curl@7.35.0-1ubuntu2.20+esm14?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.35.0-1ubuntu2.20+esm14

Affected versions

7.*

7.32.0-1ubuntu1
7.33.0-1ubuntu1
7.34.0-1ubuntu1
7.35.0-1ubuntu1
7.35.0-1ubuntu2
7.35.0-1ubuntu2.1
7.35.0-1ubuntu2.2
7.35.0-1ubuntu2.3
7.35.0-1ubuntu2.5
7.35.0-1ubuntu2.6
7.35.0-1ubuntu2.7
7.35.0-1ubuntu2.8
7.35.0-1ubuntu2.9
7.35.0-1ubuntu2.10
7.35.0-1ubuntu2.11
7.35.0-1ubuntu2.12
7.35.0-1ubuntu2.13
7.35.0-1ubuntu2.14
7.35.0-1ubuntu2.15
7.35.0-1ubuntu2.16
7.35.0-1ubuntu2.17
7.35.0-1ubuntu2.19
7.35.0-1ubuntu2.20
7.35.0-1ubuntu2.20+esm3
7.35.0-1ubuntu2.20+esm4
7.35.0-1ubuntu2.20+esm5
7.35.0-1ubuntu2.20+esm6
7.35.0-1ubuntu2.20+esm7
7.35.0-1ubuntu2.20+esm8
7.35.0-1ubuntu2.20+esm9
7.35.0-1ubuntu2.20+esm10
7.35.0-1ubuntu2.20+esm11
7.35.0-1ubuntu2.20+esm12
7.35.0-1ubuntu2.20+esm13

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "curl-udeb": "7.35.0-1ubuntu2.20+esm14",
            "libcurl3": "7.35.0-1ubuntu2.20+esm14",
            "libcurl4-gnutls-dev": "7.35.0-1ubuntu2.20+esm14",
            "libcurl3-dbgsym": "7.35.0-1ubuntu2.20+esm14",
            "libcurl3-nss": "7.35.0-1ubuntu2.20+esm14",
            "libcurl4-doc": "7.35.0-1ubuntu2.20+esm14",
            "libcurl3-udeb-dbgsym": "7.35.0-1ubuntu2.20+esm14",
            "libcurl3-gnutls-dbgsym": "7.35.0-1ubuntu2.20+esm14",
            "libcurl4-openssl-dev": "7.35.0-1ubuntu2.20+esm14",
            "libcurl4-openssl-dev-dbgsym": "7.35.0-1ubuntu2.20+esm14",
            "curl-dbgsym": "7.35.0-1ubuntu2.20+esm14",
            "curl": "7.35.0-1ubuntu2.20+esm14",
            "libcurl3-udeb": "7.35.0-1ubuntu2.20+esm14",
            "curl-udeb-dbgsym": "7.35.0-1ubuntu2.20+esm14",
            "libcurl4-nss-dev-dbgsym": "7.35.0-1ubuntu2.20+esm14",
            "libcurl3-gnutls": "7.35.0-1ubuntu2.20+esm14",
            "libcurl4-gnutls-dev-dbgsym": "7.35.0-1ubuntu2.20+esm14",
            "libcurl3-nss-dbgsym": "7.35.0-1ubuntu2.20+esm14",
            "libcurl3-dbg": "7.35.0-1ubuntu2.20+esm14",
            "libcurl4-nss-dev": "7.35.0-1ubuntu2.20+esm14"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / curl

Package

Name
curl
Purl
pkg:deb/ubuntu/curl@7.47.0-1ubuntu2.19+esm7?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.47.0-1ubuntu2.19+esm7

Affected versions

7.*

7.43.0-1ubuntu2
7.45.0-1ubuntu1
7.46.0-1ubuntu1
7.47.0-1ubuntu1
7.47.0-1ubuntu2
7.47.0-1ubuntu2.1
7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.3
7.47.0-1ubuntu2.4
7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.6
7.47.0-1ubuntu2.7
7.47.0-1ubuntu2.8
7.47.0-1ubuntu2.9
7.47.0-1ubuntu2.11
7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.14
7.47.0-1ubuntu2.15
7.47.0-1ubuntu2.16
7.47.0-1ubuntu2.18
7.47.0-1ubuntu2.19
7.47.0-1ubuntu2.19+esm1
7.47.0-1ubuntu2.19+esm2
7.47.0-1ubuntu2.19+esm3
7.47.0-1ubuntu2.19+esm4
7.47.0-1ubuntu2.19+esm5
7.47.0-1ubuntu2.19+esm6

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "libcurl3": "7.47.0-1ubuntu2.19+esm7",
            "libcurl4-gnutls-dev": "7.47.0-1ubuntu2.19+esm7",
            "libcurl3-dbgsym": "7.47.0-1ubuntu2.19+esm7",
            "libcurl3-nss": "7.47.0-1ubuntu2.19+esm7",
            "libcurl4-doc": "7.47.0-1ubuntu2.19+esm7",
            "libcurl3-gnutls-dbgsym": "7.47.0-1ubuntu2.19+esm7",
            "libcurl4-openssl-dev": "7.47.0-1ubuntu2.19+esm7",
            "libcurl4-openssl-dev-dbgsym": "7.47.0-1ubuntu2.19+esm7",
            "curl-dbgsym": "7.47.0-1ubuntu2.19+esm7",
            "curl": "7.47.0-1ubuntu2.19+esm7",
            "libcurl4-nss-dev-dbgsym": "7.47.0-1ubuntu2.19+esm7",
            "libcurl3-gnutls": "7.47.0-1ubuntu2.19+esm7",
            "libcurl4-gnutls-dev-dbgsym": "7.47.0-1ubuntu2.19+esm7",
            "libcurl3-nss-dbgsym": "7.47.0-1ubuntu2.19+esm7",
            "libcurl3-dbg": "7.47.0-1ubuntu2.19+esm7",
            "libcurl4-nss-dev": "7.47.0-1ubuntu2.19+esm7"
        }
    ]
}

Ubuntu:18.04:LTS / curl

Package

Name
curl
Purl
pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.22?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.58.0-2ubuntu3.22

Affected versions

7.*

7.55.1-1ubuntu2
7.55.1-1ubuntu2.1
7.57.0-1ubuntu1
7.58.0-2ubuntu1
7.58.0-2ubuntu2
7.58.0-2ubuntu3
7.58.0-2ubuntu3.1
7.58.0-2ubuntu3.2
7.58.0-2ubuntu3.3
7.58.0-2ubuntu3.5
7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.7
7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.10
7.58.0-2ubuntu3.12
7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.14
7.58.0-2ubuntu3.15
7.58.0-2ubuntu3.16
7.58.0-2ubuntu3.17
7.58.0-2ubuntu3.18
7.58.0-2ubuntu3.19
7.58.0-2ubuntu3.20
7.58.0-2ubuntu3.21

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "curl-dbgsym": "7.58.0-2ubuntu3.22",
            "curl": "7.58.0-2ubuntu3.22",
            "libcurl4": "7.58.0-2ubuntu3.22",
            "libcurl4-gnutls-dev": "7.58.0-2ubuntu3.22",
            "libcurl4-dbgsym": "7.58.0-2ubuntu3.22",
            "libcurl3-nss": "7.58.0-2ubuntu3.22",
            "libcurl4-doc": "7.58.0-2ubuntu3.22",
            "libcurl3-nss-dbgsym": "7.58.0-2ubuntu3.22",
            "libcurl3-gnutls": "7.58.0-2ubuntu3.22",
            "libcurl3-gnutls-dbgsym": "7.58.0-2ubuntu3.22",
            "libcurl4-openssl-dev": "7.58.0-2ubuntu3.22",
            "libcurl4-nss-dev": "7.58.0-2ubuntu3.22"
        }
    ]
}

Ubuntu:20.04:LTS / curl

Package

Name
curl
Purl
pkg:deb/ubuntu/curl@7.68.0-1ubuntu2.15?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.68.0-1ubuntu2.15

Affected versions

7.*

7.65.3-1ubuntu3
7.65.3-1ubuntu4
7.66.0-1ubuntu1
7.67.0-2ubuntu1
7.68.0-1ubuntu1
7.68.0-1ubuntu2
7.68.0-1ubuntu2.1
7.68.0-1ubuntu2.2
7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.5
7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.10
7.68.0-1ubuntu2.11
7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.13
7.68.0-1ubuntu2.14

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "curl-dbgsym": "7.68.0-1ubuntu2.15",
            "curl": "7.68.0-1ubuntu2.15",
            "libcurl4": "7.68.0-1ubuntu2.15",
            "libcurl4-gnutls-dev": "7.68.0-1ubuntu2.15",
            "libcurl4-dbgsym": "7.68.0-1ubuntu2.15",
            "libcurl3-nss": "7.68.0-1ubuntu2.15",
            "libcurl4-doc": "7.68.0-1ubuntu2.15",
            "libcurl3-nss-dbgsym": "7.68.0-1ubuntu2.15",
            "libcurl3-gnutls": "7.68.0-1ubuntu2.15",
            "libcurl3-gnutls-dbgsym": "7.68.0-1ubuntu2.15",
            "libcurl4-openssl-dev": "7.68.0-1ubuntu2.15",
            "libcurl4-nss-dev": "7.68.0-1ubuntu2.15"
        }
    ]
}

Ubuntu:22.04:LTS / curl

Package

Name
curl
Purl
pkg:deb/ubuntu/curl@7.81.0-1ubuntu1.7?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.81.0-1ubuntu1.7

Affected versions

7.*

7.74.0-1.3ubuntu2
7.74.0-1.3ubuntu3
7.80.0-3
7.81.0-1
7.81.0-1ubuntu1.1
7.81.0-1ubuntu1.2
7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.4
7.81.0-1ubuntu1.6

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "curl-dbgsym": "7.81.0-1ubuntu1.7",
            "curl": "7.81.0-1ubuntu1.7",
            "libcurl4": "7.81.0-1ubuntu1.7",
            "libcurl4-gnutls-dev": "7.81.0-1ubuntu1.7",
            "libcurl4-dbgsym": "7.81.0-1ubuntu1.7",
            "libcurl3-nss": "7.81.0-1ubuntu1.7",
            "libcurl4-doc": "7.81.0-1ubuntu1.7",
            "libcurl3-nss-dbgsym": "7.81.0-1ubuntu1.7",
            "libcurl3-gnutls": "7.81.0-1ubuntu1.7",
            "libcurl3-gnutls-dbgsym": "7.81.0-1ubuntu1.7",
            "libcurl4-openssl-dev": "7.81.0-1ubuntu1.7",
            "libcurl4-nss-dev": "7.81.0-1ubuntu1.7"
        }
    ]
}