Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-27775

Опубликовано: 27 апр. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

A vulnerability was found in curl. This security flaw occurs due to errors in the logic where the config matching function did not take the IPv6 address zone id into account. This issue can lead to curl reusing the wrong connection when one transfer uses a zone id, and the subsequent transfer uses another.

Отчет

This flaw does not affect the dotnet product because the version shipped is outside of the affected range.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 3.1 on Red Hat Enterprise Linuxrh-dotnet31-curlNot affected
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlNot affected
Red Hat Enterprise Linux 8curlNot affected
Red Hat JBoss Core ServicescurlNot affected
Red Hat Software Collectionshttpd24-curlNot affected
Red Hat Enterprise Linux 9curlFixedRHSA-2022:829915.11.2022
Red Hat Enterprise Linux 9curlFixedRHSA-2022:829915.11.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2078388curl: bad local IPv6 connection reuse

EPSS

Процентиль: 30%
0.00105
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

CVSS3: 7.5
nvd
около 3 лет назад

An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

CVSS3: 7.5
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 7.5
debian
около 3 лет назад

An information disclosure vulnerability exists in curl 7.65.0 to 7.82. ...

rocky
больше 2 лет назад

Low: curl security update

EPSS

Процентиль: 30%
0.00105
Низкий

7.5 High

CVSS3