Critical severity9.8NVD Advisory· Published Jul 7, 2022· Updated Jun 17, 2026
CVE-2022-32207
CVE-2022-32207
Description
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- osv-coords8 versionspkg:rpm/almalinux/curlpkg:rpm/almalinux/curl-minimalpkg:rpm/almalinux/libcurlpkg:rpm/almalinux/libcurl-develpkg:rpm/almalinux/libcurl-minimalpkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4
< 7.76.1-14.el9_0.5+ 7 more
- (no CPE)range: < 7.76.1-14.el9_0.5
- (no CPE)range: < 7.76.1-14.el9_0.5
- (no CPE)range: < 7.76.1-14.el9_0.5
- (no CPE)range: < 7.76.1-14.el9_0.5
- (no CPE)range: < 7.76.1-14.el9_0.5
- (no CPE)range: < 7.79.1-150400.5.3.1
- (no CPE)range: < 7.84.0-1.1
- (no CPE)range: < 7.79.1-150400.5.3.1
Patches
Vulnerability mechanics
References
8- hackerone.com/reports/1573634nvdExploitThird Party Advisory
- seclists.org/fulldisclosure/2022/Oct/28nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2022/Oct/41nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/nvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202212-01nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20220915-0003/nvdThird Party Advisory
- support.apple.com/kb/HT213488nvdThird Party Advisory
- www.debian.org/security/2022/dsa-5197nvdThird Party Advisory
News mentions
0No linked articles in our index yet.