NA

CVE-2022-43552

Published: 09/02/2023 Updated: 27/03/2024
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

haxx curl

apple macos

splunk universal forwarder 9.1.0

splunk universal forwarder

Vendor Advisories

Several security issues were fixed in curl ...
Debian Bug report logs - #1026830 curl: CVE-2022-43552: HTTP Proxy deny use-after-free Package: src:curl; Maintainer for src:curl is Alessandro Ghedini &lt;ghedo@debianorg&gt;; Reported by: Salvatore Bonaccorso &lt;carnil@debianorg&gt; Date: Wed, 21 Dec 2022 20:33:06 UTC Severity: important Tags: security, upstream Found in v ...
Debian Bug report logs - #1026829 curl: CVE-2022-43551: Another HSTS bypass via IDN Package: src:curl; Maintainer for src:curl is Alessandro Ghedini &lt;ghedo@debianorg&gt;; Reported by: Salvatore Bonaccorso &lt;carnil@debianorg&gt; Date: Wed, 21 Dec 2022 20:33:03 UTC Severity: important Tags: security, upstream Found in vers ...
Two vulnerabilities were discovered in Curl, an easy-to-use client-side URL transfer library, which could result in denial of service or information disclosure For the stable distribution (bullseye), these problems have been fixed in version 7740-13+deb11u5 This update also revises the fix for CVE-2022-27774 released in DSA-5197-1 We recommen ...
Synopsis Low: curl security update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for curl is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of ...
Synopsis Low: curl security update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for curl is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a security impact of ...
Synopsis Important: Red Hat JBoss Core Services Apache HTTP Server 2451 SP2 security update Type/Severity Security Advisory: Important Topic Red Hat JBoss Core Services Apache HTTP Server 2451 Service Pack 2 is now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Sco ...
Synopsis Important: Red Hat JBoss Core Services Apache HTTP Server 2451 SP2 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat JBoss Core Services Apache HTTP Server 2 ...
Synopsis Low: curl security and bug fix update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for curl is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a securi ...
概述 Important: Updated RHEL-7-based Middleware container images 类型/严重性 Security Advisory: Important 标题 Updated RHEL-7-based Middleware container images are now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives ...
Synopsis Important: Self Node Remediation Operator 051 security update Type/Severity Security Advisory: Important Topic This is an updated version of the Self Node Remediation Operator This Operator is delivered by Red Hat Workload AvailabilityRed Hat Product Security has rated this update as having a security impact of Important A Commo ...
A vulnerability was found in curl This issue occurs due to an erroneous function A malicious server could make curl within Network Security Services (NSS) get stuck in a never-ending busy loop when trying to retrieve that information This flaw allows an Infinite Loop, affecting system availability (CVE-2022-27781) A vulnerability was found in c ...
A vulnerability was found in curl In this issue, curl can be asked to tunnel all protocols virtually it supports through an HTTP proxy HTTP proxies can deny these tunnel operations using an appropriate HTTP error response code When getting denied to tunnel the specific SMB or TELNET protocols, curl can use a heap-allocated struct after it has be ...
Description<!---->A vulnerability was found in curl In this issue, curl can be asked to tunnel all protocols virtually it supports through an HTTP proxy HTTP proxies can deny these tunnel operations using an appropriate HTTP error response code When getting denied to tunnel the specific SMB or TELNET protocols, curl can use a heap-allocated stru ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the&nbsp;Apple security updates&nbsp;page Apple security documents reference vulnerabilities by&nbsp;CVE-ID&nbsp ...