Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:8299

Опубликовано: 15 нояб. 2022
Источник: rocky
Оценка: Low

Описание

Low: curl security update

The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.

Security Fix(es):

  • curl: bad local IPv6 connection reuse (CVE-2022-27775)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9.1 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
curlx86_6419.el9_1.1curl-7.76.1-19.el9_1.1.x86_64.rpm
curl-minimalx86_6419.el9_1.1curl-minimal-7.76.1-19.el9_1.1.x86_64.rpm
libcurlx86_6419.el9_1.1libcurl-7.76.1-19.el9_1.1.x86_64.rpm
libcurl-minimalx86_6419.el9_1.1libcurl-minimal-7.76.1-19.el9_1.1.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

CVSS3: 7.5
redhat
около 3 лет назад

An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

CVSS3: 7.5
nvd
около 3 лет назад

An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

CVSS3: 7.5
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 7.5
debian
около 3 лет назад

An information disclosure vulnerability exists in curl 7.65.0 to 7.82. ...