7.5
CVSSv2

CVE-2022-32207

Published: 07/07/2022 Updated: 27/03/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

haxx curl

fedoraproject fedora 35

debian debian linux 11.0

netapp element software -

netapp clustered data ontap -

netapp solidfire -

netapp hci management node -

netapp bootstrap_os -

netapp h300s_firmware -

netapp h500s_firmware -

netapp h700s_firmware -

netapp h410s_firmware -

apple macos

splunk universal forwarder 9.1.0

splunk universal forwarder

Vendor Advisories

Debian Bug report logs - #1057645 curl: CVE-2023-46219 Package: src:curl; Maintainer for src:curl is Debian Curl Maintainers &lt;team+curl@trackerdebianorg&gt;; Reported by: Salvatore Bonaccorso &lt;carnil@debianorg&gt; Date: Wed, 6 Dec 2023 13:45:01 UTC Severity: important Tags: security, upstream Found in versions curl/8 ...
Several security issues were fixed in curl ...
Synopsis Moderate: curl security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for curl is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a security ...
Synopsis Moderate: Red Hat JBoss Core Services Apache HTTP Server 2451 SP1 security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat JBoss Core ServicesRed Hat Product Securi ...
Synopsis Important: Red Hat JBoss Core Services Apache HTTP Server 2451 SP1 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Core ServicesRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base sco ...
Multiple security vulnerabilities have been discovered in cURL, an URL transfer library These flaws may allow remote attackers to obtain sensitive information, leak authentication or cookie header data or facilitate a denial of service attack For the stable distribution (bullseye), these problems have been fixed in version 7740-13+deb11u2 We ...
A vulnerability was found in curl This issue occurs because a malicious server can serve excessive amounts of `Set-Cookie:` headers in an HTTP response to curl, which stores all of them This flaw leads to a denial of service, either by mistake or by a malicious actor (CVE-2022-32205) A vulnerability was found in curl This issue occurs because t ...
A vulnerability was found in curl This issue occurs because when curl saves cookies, alt-svc, and HSTS data to local files, it makes the operation atomic by finalizing the process with a rename from a temporary name to the final target file name This flaw leads to unpreserved file permissions, either by mistake or by a malicious actor ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2817 curl, libcurl-compat, libcurl-gnutls 7831-1 7840-1 Unknown Fixed curlse/docs/CVE-2022-32207html githubc ...
A vulnerability was found in curl This issue occurs because a malicious server can serve excessive amounts of `Set-Cookie:` headers in an HTTP response to curl, which stores all of them This flaw leads to a denial of service, either by mistake or by a malicious actor (CVE-2022-32205) A vulnerability was found in curl This issue occurs because t ...
A vulnerability was found in curl This issue occurs because a malicious server can serve excessive amounts of `Set-Cookie:` headers in an HTTP response to curl, which stores all of them This flaw leads to a denial of service, either by mistake or by a malicious actor (CVE-2022-32205) A vulnerability was found in curl This issue occurs because t ...