Security Fix(es):
A vulnerability was found in curl. This issue occurs because it mishandles message verification failures when curl does FTP transfers secured by krb5. This flaw makes it possible for a Man-in-the-middle attack to go unnoticed and allows data injection into the client.(CVE-2022-32208)
A vulnerability was found in curl. This issue occurs because the number of acceptable "links" in the "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps. This flaw leads to a denial of service, either by mistake or by a malicious actor.(CVE-2022-32206)
A vulnerability was found in curl. This issue occurs because when curl saves cookies, alt-svc, and HSTS data to local files, it makes the operation atomic by finalizing the process with a rename from a temporary name to the final target file name. This flaw leads to unpreserved file permissions, either by mistake or by a malicious actor.(CVE-2022-32207)
A vulnerability was found in curl. This issue occurs because a malicious server can serve excessive amounts of Set-Cookie: headers in an HTTP response to curl, which stores all of them. This flaw leads to a denial of service, either by mistake or by a malicious actor.(CVE-2022-32205)
{
"severity": "Medium"
}{
"x86_64": [
"libcurl-devel-7.71.1-15.oe1.x86_64.rpm",
"curl-7.71.1-15.oe1.x86_64.rpm",
"curl-debuginfo-7.71.1-15.oe1.x86_64.rpm",
"curl-debugsource-7.71.1-15.oe1.x86_64.rpm",
"libcurl-7.71.1-15.oe1.x86_64.rpm"
],
"aarch64": [
"curl-debugsource-7.71.1-15.oe1.aarch64.rpm",
"curl-debuginfo-7.71.1-15.oe1.aarch64.rpm",
"libcurl-devel-7.71.1-15.oe1.aarch64.rpm",
"libcurl-7.71.1-15.oe1.aarch64.rpm",
"curl-7.71.1-15.oe1.aarch64.rpm"
],
"src": [
"curl-7.71.1-15.oe1.src.rpm"
],
"noarch": [
"curl-help-7.71.1-15.oe1.noarch.rpm"
]
}
{
"x86_64": [
"curl-7.71.1-15.oe1.x86_64.rpm",
"libcurl-devel-7.71.1-15.oe1.x86_64.rpm",
"curl-debuginfo-7.71.1-15.oe1.x86_64.rpm",
"curl-debugsource-7.71.1-15.oe1.x86_64.rpm",
"libcurl-7.71.1-15.oe1.x86_64.rpm"
],
"aarch64": [
"curl-debuginfo-7.71.1-15.oe1.aarch64.rpm",
"libcurl-devel-7.71.1-15.oe1.aarch64.rpm",
"curl-7.71.1-15.oe1.aarch64.rpm",
"libcurl-7.71.1-15.oe1.aarch64.rpm",
"curl-debugsource-7.71.1-15.oe1.aarch64.rpm"
],
"src": [
"curl-7.71.1-15.oe1.src.rpm"
],
"noarch": [
"curl-help-7.71.1-15.oe1.noarch.rpm"
]
}
{
"x86_64": [
"curl-debugsource-7.79.1-7.oe2203.x86_64.rpm",
"libcurl-devel-7.79.1-7.oe2203.x86_64.rpm",
"curl-debuginfo-7.79.1-7.oe2203.x86_64.rpm",
"curl-7.79.1-7.oe2203.x86_64.rpm",
"libcurl-7.79.1-7.oe2203.x86_64.rpm"
],
"aarch64": [
"curl-7.79.1-7.oe2203.aarch64.rpm",
"curl-debuginfo-7.79.1-7.oe2203.aarch64.rpm",
"libcurl-7.79.1-7.oe2203.aarch64.rpm",
"curl-debugsource-7.79.1-7.oe2203.aarch64.rpm",
"libcurl-devel-7.79.1-7.oe2203.aarch64.rpm"
],
"src": [
"curl-7.79.1-7.oe2203.src.rpm"
],
"noarch": [
"curl-help-7.79.1-7.oe2203.noarch.rpm"
]
}