Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-32207

Опубликовано: 07 июл. 2022
Источник: debian
EPSS Низкий

Описание

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed7.84.0-1package
curlnot-affectedbusterpackage
curlnot-affectedstretchpackage

Примечания

  • https://curl.se/docs/CVE-2022-32207.html

  • Introduced by: https://github.com/curl/curl/commit/b834890a3fa3f525cd8ef4e99554cdb4558d7e1b (curl-7_69_0)

  • Fixed by: https://github.com/curl/curl/commit/20f9dd6bae50b7223171b17ba7798946e74f877f (curl-7_84_0)

EPSS

Процентиль: 42%
0.00195
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 3 лет назад

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

CVSS3: 9.8
redhat
около 3 лет назад

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

CVSS3: 9.8
nvd
около 3 лет назад

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

CVSS3: 9.8
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 9.8
github
около 3 лет назад

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

EPSS

Процентиль: 42%
0.00195
Низкий