Related Vulnerabilities: CVE-2022-32208  

A vulnerability was found in curl. This issue occurs because it mishandles message verification failures when curl does FTP transfers secured by krb5. This flaw makes it possible for a Man-in-the-middle attack to go unnoticed and allows data injection into the client.

Description

A vulnerability was found in curl. This issue occurs because it mishandles message verification failures when curl does FTP transfers secured by krb5. This flaw makes it possible for a Man-in-the-middle attack to go unnoticed and allows data injection into the client.

Additional Information

  • Bugzilla 2099306: CVE-2022-32208 curl: FTP-KRB bad message verification
  • CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel
  • FAQ: Frequently asked questions about CVE-2022-32208