VYPR

rpm package

almalinux/libcurl-devel

pkg:rpm/almalinux/libcurl-devel

Vulnerabilities (32)

  • CVE-2022-35252LowSep 23, 2022
    affected < 7.76.1-23.el9fixed 7.76.1-23.el9

    When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

  • CVE-2022-32208MedJul 7, 2022
    affected < 7.76.1-14.el9_0.5fixed 7.76.1-14.el9_0.5

    When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.

  • CVE-2022-32207CriJul 7, 2022
    affected < 7.76.1-14.el9_0.5fixed 7.76.1-14.el9_0.5

    When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the targ

  • CVE-2022-32206MedJul 7, 2022
    affected < 7.76.1-14.el9_0.5fixed 7.76.1-14.el9_0.5

    curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to ins

  • CVE-2022-27782HigJun 2, 2022
    affected < 7.61.1-22.el8_6.3fixed 7.61.1-22.el8_6.3

    libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, s

  • CVE-2022-27776MedJun 2, 2022
    affected < 7.61.1-22.el8_6.3fixed 7.61.1-22.el8_6.3

    A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

  • CVE-2022-27775HigJun 2, 2022
    affected < 7.76.1-19.el9fixed 7.76.1-19.el9

    An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

  • CVE-2022-27774MedJun 2, 2022
    affected < 7.61.1-22.el8_6.3fixed 7.61.1-22.el8_6.3

    An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on d

  • CVE-2022-22576HigMay 26, 2022
    affected < 7.61.1-22.el8_6.3fixed 7.61.1-22.el8_6.3

    An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL

  • CVE-2021-22925MedAug 5, 2021
    affected < 7.61.1-22.el8fixed 7.61.1-22.el8

    curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized

  • CVE-2021-22898LowJun 11, 2021
    affected < 7.61.1-22.el8fixed 7.61.1-22.el8

    curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could

  • CVE-2021-22876MedApr 1, 2021
    affected < 7.61.1-22.el8fixed 7.61.1-22.el8

    curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP

Page 2 of 2