rpm package
almalinux/curl-minimal
pkg:rpm/almalinux/curl-minimal
Vulnerabilities (24)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-32208 | Med | 5.9 | < 7.76.1-14.el9_0.5 | 7.76.1-14.el9_0.5 | Jul 7, 2022 | When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client. | |
| CVE-2022-32207 | Cri | 9.8 | < 7.76.1-14.el9_0.5 | 7.76.1-14.el9_0.5 | Jul 7, 2022 | When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the targ | |
| CVE-2022-32206 | Med | 6.5 | < 7.76.1-14.el9_0.5 | 7.76.1-14.el9_0.5 | Jul 7, 2022 | curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to ins | |
| CVE-2022-27775 | Hig | 7.5 | < 7.76.1-19.el9 | 7.76.1-19.el9 | Jun 2, 2022 | An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead. |
- affected < 7.76.1-14.el9_0.5fixed 7.76.1-14.el9_0.5
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
- affected < 7.76.1-14.el9_0.5fixed 7.76.1-14.el9_0.5
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the targ
- affected < 7.76.1-14.el9_0.5fixed 7.76.1-14.el9_0.5
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to ins
- affected < 7.76.1-19.el9fixed 7.76.1-19.el9
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.
Page 2 of 2