ID

VAR-202210-1888


CVE

CVE-2022-32221


TITLE

Haxx  of  cURL  Vulnerability related to resource leakage to the wrong area in products from other vendors

Trust: 0.8

sources: JVNDB: JVNDB-2022-023343

DESCRIPTION

When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST. Haxx of cURL Products from other vendors have vulnerabilities related to resource disclosure to the wrong domain.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. (CVE-2022-42915). ========================================================================== Ubuntu Security Notice USN-5702-1 October 26, 2022 curl vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in curl. Software Description: - curl: HTTP, HTTPS, and FTP client and client libraries Details: Robby Simpson discovered that curl incorrectly handled certain POST operations after PUT operations. (CVE-2022-32221) Hiroki Kurosawa discovered that curl incorrectly handled parsing .netrc files. If an attacker were able to provide a specially crafted .netrc file, this issue could cause curl to crash, resulting in a denial of service. This issue only affected Ubuntu 22.10. (CVE-2022-35260) It was discovered that curl incorrectly handled certain HTTP proxy return codes. A remote attacker could use this issue to cause curl to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-42915) Hiroki Kurosawa discovered that curl incorrectly handled HSTS support when certain hostnames included IDN characters. A remote attacker could possibly use this issue to cause curl to use unencrypted connections. This issue only affected Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-42916) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: curl 7.85.0-1ubuntu0.1 libcurl3-gnutls 7.85.0-1ubuntu0.1 libcurl3-nss 7.85.0-1ubuntu0.1 libcurl4 7.85.0-1ubuntu0.1 Ubuntu 22.04 LTS: curl 7.81.0-1ubuntu1.6 libcurl3-gnutls 7.81.0-1ubuntu1.6 libcurl3-nss 7.81.0-1ubuntu1.6 libcurl4 7.81.0-1ubuntu1.6 Ubuntu 20.04 LTS: curl 7.68.0-1ubuntu2.14 libcurl3-gnutls 7.68.0-1ubuntu2.14 libcurl3-nss 7.68.0-1ubuntu2.14 libcurl4 7.68.0-1ubuntu2.14 Ubuntu 18.04 LTS: curl 7.58.0-2ubuntu3.21 libcurl3-gnutls 7.58.0-2ubuntu3.21 libcurl3-nss 7.58.0-2ubuntu3.21 libcurl4 7.58.0-2ubuntu3.21 In general, a standard system update will make all the necessary changes. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202212-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: curl: Multiple Vulnerabilities Date: December 19, 2022 Bugs: #803308, #813270, #841302, #843824, #854708, #867679, #878365 ID: 202212-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in curl, the worst of which could result in arbitrary code execution. Background ========= A command line tool and library for transferring data with URLs. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/curl < 7.86.0 >= 7.86.0 Description ========== Multiple vulnerabilities have been discovered in curl. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All curl users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/curl-7.86.0" References ========= [ 1 ] CVE-2021-22922 https://nvd.nist.gov/vuln/detail/CVE-2021-22922 [ 2 ] CVE-2021-22923 https://nvd.nist.gov/vuln/detail/CVE-2021-22923 [ 3 ] CVE-2021-22925 https://nvd.nist.gov/vuln/detail/CVE-2021-22925 [ 4 ] CVE-2021-22926 https://nvd.nist.gov/vuln/detail/CVE-2021-22926 [ 5 ] CVE-2021-22945 https://nvd.nist.gov/vuln/detail/CVE-2021-22945 [ 6 ] CVE-2021-22946 https://nvd.nist.gov/vuln/detail/CVE-2021-22946 [ 7 ] CVE-2021-22947 https://nvd.nist.gov/vuln/detail/CVE-2021-22947 [ 8 ] CVE-2022-22576 https://nvd.nist.gov/vuln/detail/CVE-2022-22576 [ 9 ] CVE-2022-27774 https://nvd.nist.gov/vuln/detail/CVE-2022-27774 [ 10 ] CVE-2022-27775 https://nvd.nist.gov/vuln/detail/CVE-2022-27775 [ 11 ] CVE-2022-27776 https://nvd.nist.gov/vuln/detail/CVE-2022-27776 [ 12 ] CVE-2022-27779 https://nvd.nist.gov/vuln/detail/CVE-2022-27779 [ 13 ] CVE-2022-27780 https://nvd.nist.gov/vuln/detail/CVE-2022-27780 [ 14 ] CVE-2022-27781 https://nvd.nist.gov/vuln/detail/CVE-2022-27781 [ 15 ] CVE-2022-27782 https://nvd.nist.gov/vuln/detail/CVE-2022-27782 [ 16 ] CVE-2022-30115 https://nvd.nist.gov/vuln/detail/CVE-2022-30115 [ 17 ] CVE-2022-32205 https://nvd.nist.gov/vuln/detail/CVE-2022-32205 [ 18 ] CVE-2022-32206 https://nvd.nist.gov/vuln/detail/CVE-2022-32206 [ 19 ] CVE-2022-32207 https://nvd.nist.gov/vuln/detail/CVE-2022-32207 [ 20 ] CVE-2022-32208 https://nvd.nist.gov/vuln/detail/CVE-2022-32208 [ 21 ] CVE-2022-32221 https://nvd.nist.gov/vuln/detail/CVE-2022-32221 [ 22 ] CVE-2022-35252 https://nvd.nist.gov/vuln/detail/CVE-2022-35252 [ 23 ] CVE-2022-35260 https://nvd.nist.gov/vuln/detail/CVE-2022-35260 [ 24 ] CVE-2022-42915 https://nvd.nist.gov/vuln/detail/CVE-2022-42915 [ 25 ] CVE-2022-42916 https://nvd.nist.gov/vuln/detail/CVE-2022-42916 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202212-01 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2023-01-23-4 macOS Ventura 13.2 macOS Ventura 13.2 addresses the following issues. Information about the security content is also available at https://support.apple.com/HT213605. AppleMobileFileIntegrity Available for: macOS Ventura Impact: An app may be able to access user-sensitive data Description: This issue was addressed by enabling hardened runtime. CVE-2023-23499: Wojciech Reguła (@_r3ggi) of SecuRing (wojciechregula.blog) curl Available for: macOS Ventura Impact: Multiple issues in curl Description: Multiple issues were addressed by updating to curl version 7.86.0. CVE-2022-42915 CVE-2022-42916 CVE-2022-32221 CVE-2022-35260 dcerpc Available for: macOS Ventura Impact: Mounting a maliciously crafted Samba network share may lead to arbitrary code execution Description: A buffer overflow issue was addressed with improved memory handling. CVE-2023-23513: Dimitrios Tatsis and Aleksandar Nikolic of Cisco Talos DiskArbitration Available for: macOS Ventura Impact: An encrypted volume may be unmounted and remounted by a different user without prompting for the password Description: A logic issue was addressed with improved state management. CVE-2023-23493: Oliver Norpoth (@norpoth) of KLIXX GmbH (klixx.com) ImageIO Available for: macOS Ventura Impact: Processing an image may lead to a denial-of-service Description: A memory corruption issue was addressed with improved state management. CVE-2023-23519: Yiğit Can YILMAZ (@yilmazcanyigit) Intel Graphics Driver Available for: macOS Ventura Impact: An app may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved bounds checks. CVE-2023-23507: an anonymous researcher Kernel Available for: macOS Ventura Impact: An app may be able to leak sensitive kernel state Description: The issue was addressed with improved memory handling. CVE-2023-23500: Pan ZhenPeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. (@starlabs_sg) Kernel Available for: macOS Ventura Impact: An app may be able to determine kernel memory layout Description: An information disclosure issue was addressed by removing the vulnerable code. CVE-2023-23502: Pan ZhenPeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. (@starlabs_sg) Kernel Available for: macOS Ventura Impact: An app may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved memory handling. CVE-2023-23504: Adam Doupé of ASU SEFCOM libxpc Available for: macOS Ventura Impact: An app may be able to access user-sensitive data Description: A permissions issue was addressed with improved validation. CVE-2023-23506: Guilherme Rambo of Best Buddy Apps (rambo.codes) Mail Drafts Available for: macOS Ventura Impact: The quoted original message may be selected from the wrong email when forwarding an email from an Exchange account Description: A logic issue was addressed with improved state management. CVE-2023-23498: an anonymous researcher Maps Available for: macOS Ventura Impact: An app may be able to bypass Privacy preferences Description: A logic issue was addressed with improved state management. CVE-2023-23503: an anonymous researcher PackageKit Available for: macOS Ventura Impact: An app may be able to gain root privileges Description: A logic issue was addressed with improved state management. CVE-2023-23497: Mickey Jin (@patch1t) Safari Available for: macOS Ventura Impact: An app may be able to access a user’s Safari history Description: A permissions issue was addressed with improved validation. CVE-2023-23510: Guilherme Rambo of Best Buddy Apps (rambo.codes) Safari Available for: macOS Ventura Impact: Visiting a website may lead to an app denial-of-service Description: The issue was addressed with improved handling of caches. CVE-2023-23512: Adriatik Raci Screen Time Available for: macOS Ventura Impact: An app may be able to access information about a user’s contacts Description: A privacy issue was addressed with improved private data redaction for log entries. CVE-2023-23505: Wojciech Reguła of SecuRing (wojciechregula.blog) Vim Available for: macOS Ventura Impact: Multiple issues in Vim Description: A use after free issue was addressed with improved memory management. CVE-2022-3705 Weather Available for: macOS Ventura Impact: An app may be able to bypass Privacy preferences Description: The issue was addressed with improved memory handling. CVE-2023-23511: Wojciech Regula of SecuRing (wojciechregula.blog), an anonymous researcher WebKit Available for: macOS Ventura Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: The issue was addressed with improved checks. WebKit Bugzilla: 245464 CVE-2023-23496: ChengGang Wu, Yan Kang, YuHao Hu, Yue Sun, Jiming Wang, JiKai Ren and Hang Shu of Institute of Computing Technology, Chinese Academy of Sciences WebKit Available for: macOS Ventura Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 248268 CVE-2023-23518: YeongHyeon Choi (@hyeon101010), Hyeon Park (@tree_segment), SeOk JEON (@_seokjeon), YoungSung Ahn (@_ZeroSung), JunSeo Bae (@snakebjs0107), Dohyun Lee (@l33d0hyun) of Team ApplePIE WebKit Bugzilla: 248268 CVE-2023-23517: YeongHyeon Choi (@hyeon101010), Hyeon Park (@tree_segment), SeOk JEON (@_seokjeon), YoungSung Ahn (@_ZeroSung), JunSeo Bae (@snakebjs0107), Dohyun Lee (@l33d0hyun) of Team ApplePIE Wi-Fi Available for: macOS Ventura Impact: An app may be able to disclose kernel memory Description: The issue was addressed with improved memory handling. CVE-2023-23501: Pan ZhenPeng (@Peterpan0927) of STAR Labs SG Pte. Ltd. (@starlabs_sg) Windows Installer Available for: macOS Ventura Impact: An app may be able to bypass Privacy preferences Description: The issue was addressed with improved memory handling. CVE-2023-23508: Mickey Jin (@patch1t) Additional recognition Bluetooth We would like to acknowledge an anonymous researcher for their assistance. Kernel We would like to acknowledge Nick Stenning of Replicate for their assistance. Shortcuts We would like to acknowledge Baibhav Anand Jha from ReconWithMe and Cristian Dinca of Tudor Vianu National High School of Computer Science, Romania for their assistance. WebKit We would like to acknowledge Eliya Stein of Confiant for their assistance. macOS Ventura 13.2 may be obtained from the Mac App Store or Apple's Software Downloads web site: https://support.apple.com/downloads/ All information is also posted on the Apple Security Updates web site: https://support.apple.com/en-us/HT201222. This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEBP+4DupqR5Sgt1DB4RjMIDkeNxkFAmPPIl8ACgkQ4RjMIDke Nxnt7RAA2a0c/Ij93MfR8eiNMkIHVnr+wL+4rckVmHvs85dSHNBqQ8+kYpAs2tEk 7CVZoxAGg8LqVa6ZmBbAp5ZJGi2nV8LjOYzaWw/66d648QC2upTWJ93sWmZ7LlLb m9pcLfBsdAFPmVa8VJO0fxJGkxsCP0cQiBl+f9R4ObZBBiScbHUckSmHa6Qn/Q2U VsnHnJznAlDHMXiaV3O1zKBeahkqSx/IfO04qmk8oMWh89hI53S551Z3NEx63zgd Cx8JENj2NpFlgmZ0w0Tz5ZZ3LT4Ok28ns8N762JLE2nbTfEl7rM+bjUfWg4yJ1Rp TCEelbLKfUjlrh2N1fe0XWBs9br/069QlhTBBVd/qAbUBxkS/UOlWk3Vp+TI0bkK rrXouRijzRmBBK93jfWxhyd27avqQHmc04ofjY/lNYOCcGMrr813cGKNs90aRfcg joKeC51mYJnlTyMB0nDcJx3b5+MN+Ij7Sa04B9dbH162YFxp4LsaavmR0MooN1T9 3XrXEQ71a3pvdoF1ffW9Mz7vaqhBkffnzQwWU5zY2RwDTjFyHdNyI/1JkVzYmAxq QR4uA5gCDYYk/3rzlrVot+ezHX525clTHsvEYhIfu+i1HCxqdpvfaHbn2m+i1QtU /Lzz2mySt3y0akZ2rHwPfBZ8UFfvaauyhZ3EhSP3ikGs9DOsv1w= =pcJ4 -----END PGP SIGNATURE----- . Software Description: - mysql-8.0: MySQL database - mysql-5.7: MySQL database Details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. In general, a standard system update will make all the necessary changes. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: curl security update Advisory ID: RHSA-2023:0333-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0333 Issue date: 2023-01-23 CVE Names: CVE-2022-32221 ==================================================================== 1. Summary: An update for curl is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP. Security Fix(es): * curl: POST following PUT confusion (CVE-2022-32221) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2135411 - CVE-2022-32221 curl: POST following PUT confusion 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): aarch64: curl-debuginfo-7.76.1-19.el9_1.1.aarch64.rpm curl-debugsource-7.76.1-19.el9_1.1.aarch64.rpm curl-minimal-debuginfo-7.76.1-19.el9_1.1.aarch64.rpm libcurl-debuginfo-7.76.1-19.el9_1.1.aarch64.rpm libcurl-devel-7.76.1-19.el9_1.1.aarch64.rpm libcurl-minimal-debuginfo-7.76.1-19.el9_1.1.aarch64.rpm ppc64le: curl-debuginfo-7.76.1-19.el9_1.1.ppc64le.rpm curl-debugsource-7.76.1-19.el9_1.1.ppc64le.rpm curl-minimal-debuginfo-7.76.1-19.el9_1.1.ppc64le.rpm libcurl-debuginfo-7.76.1-19.el9_1.1.ppc64le.rpm libcurl-devel-7.76.1-19.el9_1.1.ppc64le.rpm libcurl-minimal-debuginfo-7.76.1-19.el9_1.1.ppc64le.rpm s390x: curl-debuginfo-7.76.1-19.el9_1.1.s390x.rpm curl-debugsource-7.76.1-19.el9_1.1.s390x.rpm curl-minimal-debuginfo-7.76.1-19.el9_1.1.s390x.rpm libcurl-debuginfo-7.76.1-19.el9_1.1.s390x.rpm libcurl-devel-7.76.1-19.el9_1.1.s390x.rpm libcurl-minimal-debuginfo-7.76.1-19.el9_1.1.s390x.rpm x86_64: curl-debuginfo-7.76.1-19.el9_1.1.i686.rpm curl-debuginfo-7.76.1-19.el9_1.1.x86_64.rpm curl-debugsource-7.76.1-19.el9_1.1.i686.rpm curl-debugsource-7.76.1-19.el9_1.1.x86_64.rpm curl-minimal-debuginfo-7.76.1-19.el9_1.1.i686.rpm curl-minimal-debuginfo-7.76.1-19.el9_1.1.x86_64.rpm libcurl-debuginfo-7.76.1-19.el9_1.1.i686.rpm libcurl-debuginfo-7.76.1-19.el9_1.1.x86_64.rpm libcurl-devel-7.76.1-19.el9_1.1.i686.rpm libcurl-devel-7.76.1-19.el9_1.1.x86_64.rpm libcurl-minimal-debuginfo-7.76.1-19.el9_1.1.i686.rpm libcurl-minimal-debuginfo-7.76.1-19.el9_1.1.x86_64.rpm Red Hat Enterprise Linux BaseOS (v. 9): Source: curl-7.76.1-19.el9_1.1.src.rpm aarch64: curl-7.76.1-19.el9_1.1.aarch64.rpm curl-debuginfo-7.76.1-19.el9_1.1.aarch64.rpm curl-debugsource-7.76.1-19.el9_1.1.aarch64.rpm curl-minimal-7.76.1-19.el9_1.1.aarch64.rpm curl-minimal-debuginfo-7.76.1-19.el9_1.1.aarch64.rpm libcurl-7.76.1-19.el9_1.1.aarch64.rpm libcurl-debuginfo-7.76.1-19.el9_1.1.aarch64.rpm libcurl-minimal-7.76.1-19.el9_1.1.aarch64.rpm libcurl-minimal-debuginfo-7.76.1-19.el9_1.1.aarch64.rpm ppc64le: curl-7.76.1-19.el9_1.1.ppc64le.rpm curl-debuginfo-7.76.1-19.el9_1.1.ppc64le.rpm curl-debugsource-7.76.1-19.el9_1.1.ppc64le.rpm curl-minimal-7.76.1-19.el9_1.1.ppc64le.rpm curl-minimal-debuginfo-7.76.1-19.el9_1.1.ppc64le.rpm libcurl-7.76.1-19.el9_1.1.ppc64le.rpm libcurl-debuginfo-7.76.1-19.el9_1.1.ppc64le.rpm libcurl-minimal-7.76.1-19.el9_1.1.ppc64le.rpm libcurl-minimal-debuginfo-7.76.1-19.el9_1.1.ppc64le.rpm s390x: curl-7.76.1-19.el9_1.1.s390x.rpm curl-debuginfo-7.76.1-19.el9_1.1.s390x.rpm curl-debugsource-7.76.1-19.el9_1.1.s390x.rpm curl-minimal-7.76.1-19.el9_1.1.s390x.rpm curl-minimal-debuginfo-7.76.1-19.el9_1.1.s390x.rpm libcurl-7.76.1-19.el9_1.1.s390x.rpm libcurl-debuginfo-7.76.1-19.el9_1.1.s390x.rpm libcurl-minimal-7.76.1-19.el9_1.1.s390x.rpm libcurl-minimal-debuginfo-7.76.1-19.el9_1.1.s390x.rpm x86_64: curl-7.76.1-19.el9_1.1.x86_64.rpm curl-debuginfo-7.76.1-19.el9_1.1.i686.rpm curl-debuginfo-7.76.1-19.el9_1.1.x86_64.rpm curl-debugsource-7.76.1-19.el9_1.1.i686.rpm curl-debugsource-7.76.1-19.el9_1.1.x86_64.rpm curl-minimal-7.76.1-19.el9_1.1.x86_64.rpm curl-minimal-debuginfo-7.76.1-19.el9_1.1.i686.rpm curl-minimal-debuginfo-7.76.1-19.el9_1.1.x86_64.rpm libcurl-7.76.1-19.el9_1.1.i686.rpm libcurl-7.76.1-19.el9_1.1.x86_64.rpm libcurl-debuginfo-7.76.1-19.el9_1.1.i686.rpm libcurl-debuginfo-7.76.1-19.el9_1.1.x86_64.rpm libcurl-minimal-7.76.1-19.el9_1.1.i686.rpm libcurl-minimal-7.76.1-19.el9_1.1.x86_64.rpm libcurl-minimal-debuginfo-7.76.1-19.el9_1.1.i686.rpm libcurl-minimal-debuginfo-7.76.1-19.el9_1.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-32221 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. For the stable distribution (bullseye), these problems have been fixed in version 7.74.0-1.3+deb11u5. This update also revises the fix for CVE-2022-27774 released in DSA-5197-1. We recommend that you upgrade your curl packages

Trust: 2.43

sources: NVD: CVE-2022-32221 // JVNDB: JVNDB-2022-023343 // VULHUB: VHN-424148 // VULMON: CVE-2022-32221 // PACKETSTORM: 169535 // PACKETSTORM: 170303 // PACKETSTORM: 170696 // PACKETSTORM: 170729 // PACKETSTORM: 170648 // PACKETSTORM: 170777 // PACKETSTORM: 173569

AFFECTED PRODUCTS

vendor:debianmodel:linuxscope:eqversion:11.0

Trust: 1.0

vendor:haxxmodel:curlscope:ltversion:7.86.0

Trust: 1.0

vendor:applemodel:macosscope:ltversion:12.6.3

Trust: 1.0

vendor:splunkmodel:universal forwarderscope:ltversion:9.0.6

Trust: 1.0

vendor:netappmodel:h300sscope:eqversion: -

Trust: 1.0

vendor:netappmodel:h410sscope:eqversion: -

Trust: 1.0

vendor:splunkmodel:universal forwarderscope:gteversion:9.0.0

Trust: 1.0

vendor:splunkmodel:universal forwarderscope:eqversion:9.1.0

Trust: 1.0

vendor:netappmodel:h700sscope:eqversion: -

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:10.0

Trust: 1.0

vendor:splunkmodel:universal forwarderscope:ltversion:8.2.12

Trust: 1.0

vendor:netappmodel:clustered data ontapscope:eqversion: -

Trust: 1.0

vendor:netappmodel:h500sscope:eqversion: -

Trust: 1.0

vendor:splunkmodel:universal forwarderscope:gteversion:8.2.0

Trust: 1.0

vendor:debianmodel:gnu/linuxscope: - version: -

Trust: 0.8

vendor:haxxmodel:curlscope: - version: -

Trust: 0.8

vendor:netappmodel:h410sscope: - version: -

Trust: 0.8

vendor:netappmodel:h700sscope: - version: -

Trust: 0.8

vendor:netappmodel:h300sscope: - version: -

Trust: 0.8

vendor:netappmodel:h500sscope: - version: -

Trust: 0.8

vendor:netappmodel:ontapscope: - version: -

Trust: 0.8

vendor:アップルmodel:macosscope:eqversion:12.6.3

Trust: 0.8

sources: JVNDB: JVNDB-2022-023343 // NVD: CVE-2022-32221

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-32221
value: CRITICAL

Trust: 1.0

NVD: CVE-2022-32221
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202210-2214
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2022-32221
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2022-32221
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNNVD: CNNVD-202210-2214 // JVNDB: JVNDB-2022-023343 // NVD: CVE-2022-32221

PROBLEMTYPE DATA

problemtype:CWE-668

Trust: 1.1

problemtype:CWE-200

Trust: 1.0

problemtype:Leakage of resources to the wrong area (CWE-668) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-424148 // JVNDB: JVNDB-2022-023343 // NVD: CVE-2022-32221

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202210-2214

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202210-2214

PATCH

title:HT213605url:https://lists.debian.org/debian-lts-announce/2023/01/msg00028.html

Trust: 0.8

title:curl Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=216855

Trust: 0.6

title:Ubuntu Security Notice: USN-5702-2: curl vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-5702-2

Trust: 0.1

title:Ubuntu Security Notice: USN-5702-1: curl vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-5702-1

Trust: 0.1

title:Red Hat: url:https://vulmon.com/vendoradvisory?qidtp=red_hat_cve_database&qid=CVE-2022-32221

Trust: 0.1

title:IBM: Security Bulletin: The Community Edition of IBM ILOG CPLEX Optimization Studio is affected by multiple vulnerabilities in libcurl (CVE-2022-42915, CVE-2022-42916, CVE-2022-32221)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=93e8baf3e9bfd9ab92a05b44368ef244

Trust: 0.1

sources: VULMON: CVE-2022-32221 // CNNVD: CNNVD-202210-2214 // JVNDB: JVNDB-2022-023343

EXTERNAL IDS

db:NVDid:CVE-2022-32221

Trust: 4.1

db:HACKERONEid:1704017

Trust: 2.5

db:OPENWALLid:OSS-SECURITY/2023/05/17/4

Trust: 2.4

db:PACKETSTORMid:170777

Trust: 0.8

db:PACKETSTORMid:169535

Trust: 0.8

db:JVNid:JVNVU98195668

Trust: 0.8

db:ICS CERTid:ICSA-23-131-05

Trust: 0.8

db:JVNDBid:JVNDB-2022-023343

Trust: 0.8

db:PACKETSTORMid:169538

Trust: 0.7

db:PACKETSTORMid:170166

Trust: 0.6

db:AUSCERTid:ESB-2023.3143

Trust: 0.6

db:AUSCERTid:ESB-2023.3732

Trust: 0.6

db:AUSCERTid:ESB-2023.4030

Trust: 0.6

db:AUSCERTid:ESB-2022.5421

Trust: 0.6

db:AUSCERTid:ESB-2022.6333

Trust: 0.6

db:CNNVDid:CNNVD-202210-2214

Trust: 0.6

db:PACKETSTORMid:170648

Trust: 0.2

db:PACKETSTORMid:170729

Trust: 0.2

db:VULHUBid:VHN-424148

Trust: 0.1

db:VULMONid:CVE-2022-32221

Trust: 0.1

db:PACKETSTORMid:170303

Trust: 0.1

db:PACKETSTORMid:170696

Trust: 0.1

db:PACKETSTORMid:173569

Trust: 0.1

sources: VULHUB: VHN-424148 // VULMON: CVE-2022-32221 // PACKETSTORM: 169535 // PACKETSTORM: 170303 // PACKETSTORM: 170696 // PACKETSTORM: 170729 // PACKETSTORM: 170648 // PACKETSTORM: 170777 // PACKETSTORM: 173569 // CNNVD: CNNVD-202210-2214 // JVNDB: JVNDB-2022-023343 // NVD: CVE-2022-32221

REFERENCES

url:https://security.gentoo.org/glsa/202212-01

Trust: 2.6

url:http://seclists.org/fulldisclosure/2023/jan/19

Trust: 2.5

url:http://seclists.org/fulldisclosure/2023/jan/20

Trust: 2.5

url:https://hackerone.com/reports/1704017

Trust: 2.5

url:http://www.openwall.com/lists/oss-security/2023/05/17/4

Trust: 2.4

url:https://security.netapp.com/advisory/ntap-20230110-0006/

Trust: 1.7

url:https://security.netapp.com/advisory/ntap-20230208-0002/

Trust: 1.7

url:https://support.apple.com/kb/ht213604

Trust: 1.7

url:https://support.apple.com/kb/ht213605

Trust: 1.7

url:https://www.debian.org/security/2023/dsa-5330

Trust: 1.7

url:https://lists.debian.org/debian-lts-announce/2023/01/msg00028.html

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2022-32221

Trust: 1.5

url:https://access.redhat.com/security/cve/cve-2022-32221

Trust: 0.9

url:https://jvn.jp/vu/jvnvu98195668/

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-05

Trust: 0.8

url:https://www.auscert.org.au/bulletins/esb-2023.3143

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2022-32221/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2023.4030

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2023.3732

Trust: 0.6

url:https://vigilance.fr/vulnerability/curl-reuse-after-free-39731

Trust: 0.6

url:https://support.apple.com/en-us/ht213604

Trust: 0.6

url:https://packetstormsecurity.com/files/169538/ubuntu-security-notice-usn-5702-2.html

Trust: 0.6

url:https://packetstormsecurity.com/files/169535/ubuntu-security-notice-usn-5702-1.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.5421

Trust: 0.6

url:https://packetstormsecurity.com/files/170166/red-hat-security-advisory-2022-8840-01.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.6333

Trust: 0.6

url:https://packetstormsecurity.com/files/170777/debian-security-advisory-5330-1.html

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2022-42915

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2022-35260

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2022-42916

Trust: 0.3

url:https://ubuntu.com/security/notices/usn-5702-1

Trust: 0.2

url:https://access.redhat.com/security/team/contact/

Trust: 0.2

url:https://access.redhat.com/security/team/key/

Trust: 0.2

url:https://access.redhat.com/articles/11258

Trust: 0.2

url:https://access.redhat.com/security/updates/classification/#moderate

Trust: 0.2

url:https://listman.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.2

url:https://bugzilla.redhat.com/):

Trust: 0.2

url:https://ubuntu.com/security/notices/usn-5702-2

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.6

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/curl/7.68.0-1ubuntu2.14

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/curl/7.58.0-2ubuntu3.21

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/curl/7.85.0-1ubuntu0.1

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-22922

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-27782

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-27776

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-27779

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-30115

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-22576

Trust: 0.1

url:https://security.gentoo.org/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-22925

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-22926

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-27781

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-22945

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-32208

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-32206

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-32207

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-27774

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-27775

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-32205

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-27780

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-35252

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-22923

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-22946

Trust: 0.1

url:https://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-22947

Trust: 0.1

url:https://support.apple.com/ht213605.

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-23503

Trust: 0.1

url:https://support.apple.com/downloads/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-23493

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-23497

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-3705

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-23501

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-23499

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-23496

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-23498

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-23502

Trust: 0.1

url:https://www.apple.com/support/security/pgp/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-23500

Trust: 0.1

url:https://support.apple.com/en-us/ht201222.

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.32-0buntu0.20.04.1

Trust: 0.1

url:https://www.oracle.com/security-alerts/cpujan2023.html

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.32-0buntu0.22.10.1

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-21877

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-21881

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.32-0buntu0.22.04.1

Trust: 0.1

url:https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-32.html

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.41-0ubuntu0.18.04.1

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-21871

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-21867

Trust: 0.1

url:https://ubuntu.com/security/notices/usn-5823-1

Trust: 0.1

url:https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-41.html

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2023:0333

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-43552

Trust: 0.1

url:https://www.debian.org/security/

Trust: 0.1

url:https://www.debian.org/security/faq

Trust: 0.1

url:https://security-tracker.debian.org/tracker/curl

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2023:4139

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-23916

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2023-23916

Trust: 0.1

sources: VULHUB: VHN-424148 // VULMON: CVE-2022-32221 // PACKETSTORM: 169535 // PACKETSTORM: 170303 // PACKETSTORM: 170696 // PACKETSTORM: 170729 // PACKETSTORM: 170648 // PACKETSTORM: 170777 // PACKETSTORM: 173569 // CNNVD: CNNVD-202210-2214 // JVNDB: JVNDB-2022-023343 // NVD: CVE-2022-32221

CREDITS

Ubuntu

Trust: 0.2

sources: PACKETSTORM: 169535 // PACKETSTORM: 170729

SOURCES

db:VULHUBid:VHN-424148
db:VULMONid:CVE-2022-32221
db:PACKETSTORMid:169535
db:PACKETSTORMid:170303
db:PACKETSTORMid:170696
db:PACKETSTORMid:170729
db:PACKETSTORMid:170648
db:PACKETSTORMid:170777
db:PACKETSTORMid:173569
db:CNNVDid:CNNVD-202210-2214
db:JVNDBid:JVNDB-2022-023343
db:NVDid:CVE-2022-32221

LAST UPDATE DATE

2026-02-05T15:27:02.291000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-424148date:2023-03-01T00:00:00
db:CNNVDid:CNNVD-202210-2214date:2023-07-19T00:00:00
db:JVNDBid:JVNDB-2022-023343date:2023-11-28T06:56:00
db:NVDid:CVE-2022-32221date:2024-03-27T15:00:28.423

SOURCES RELEASE DATE

db:VULHUBid:VHN-424148date:2022-12-05T00:00:00
db:PACKETSTORMid:169535date:2022-10-27T13:03:39
db:PACKETSTORMid:170303date:2022-12-19T13:48:31
db:PACKETSTORMid:170696date:2023-01-24T16:40:49
db:PACKETSTORMid:170729date:2023-01-25T16:09:53
db:PACKETSTORMid:170648date:2023-01-24T16:27:29
db:PACKETSTORMid:170777date:2023-01-30T16:25:15
db:PACKETSTORMid:173569date:2023-07-18T13:47:37
db:CNNVDid:CNNVD-202210-2214date:2022-10-26T00:00:00
db:JVNDBid:JVNDB-2022-023343date:2023-11-28T00:00:00
db:NVDid:CVE-2022-32221date:2022-12-05T22:15:10.343