Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-27775

Опубликовано: 02 июн. 2022
Источник: debian

Описание

An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed7.83.0-1package
curlnot-affectedbusterpackage
curlnot-affectedstretchpackage

Примечания

  • https://curl.se/docs/CVE-2022-27775.html

  • Introduced by: https://github.com/curl/curl/commit/2d0e9b40d3237b1450cbbfbcb996da244d964898 (curl-7_65_0)

  • Fixed by: https://github.com/curl/curl/commit/058f98dc3fe595f21dc26a5b9b1699e519ba5705 (curl-7_83_0)

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

CVSS3: 7.5
redhat
около 3 лет назад

An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

CVSS3: 7.5
nvd
около 3 лет назад

An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

CVSS3: 7.5
msrc
около 3 лет назад

Описание отсутствует

rocky
больше 2 лет назад

Low: curl security update