DSA-5197-1 curl -- security update

Related Vulnerabilities: CVE-2021-22898   CVE-2021-22924   CVE-2021-22945   CVE-2021-22946   CVE-2021-22947   CVE-2022-22576   CVE-2022-27774   CVE-2022-27775   CVE-2022-27776   CVE-2022-27781   CVE-2022-27782   CVE-2022-32205   CVE-2022-32206   CVE-2022-32207   CVE-2022-32208  

Multiple security vulnerabilities have been discovered in cURL, an URL transfer library. These flaws may allow remote attackers to obtain sensitive information, leak authentication or cookie header data or facilitate a denial of service attack. For the stable distribution (bullseye), these problems have been fixed in version 7.74.0-1.3+deb11u2. We recommend that you upgrade your curl packages. For the detailed security status of curl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/curl

Debian Security Advisory

DSA-5197-1 curl -- security update

Date Reported:
01 Aug 2022
Affected Packages:
curl
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 989228, Bug 991492, Bug 1010295, Bug 1010254, Bug 1010253, Bug 1010252.
In Mitre's CVE dictionary: CVE-2021-22898, CVE-2021-22924, CVE-2021-22945, CVE-2021-22946, CVE-2021-22947, CVE-2022-22576, CVE-2022-27774, CVE-2022-27775, CVE-2022-27776, CVE-2022-27781, CVE-2022-27782, CVE-2022-32205, CVE-2022-32206, CVE-2022-32207, CVE-2022-32208.
More information:

Multiple security vulnerabilities have been discovered in cURL, an URL transfer library. These flaws may allow remote attackers to obtain sensitive information, leak authentication or cookie header data or facilitate a denial of service attack.

For the stable distribution (bullseye), these problems have been fixed in version 7.74.0-1.3+deb11u2.

We recommend that you upgrade your curl packages.

For the detailed security status of curl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/curl