Количество 16
Количество 16

CVE-2022-32221
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.

CVE-2022-32221
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.

CVE-2022-32221
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.

CVE-2022-32221
CVE-2022-32221
When doing HTTP(S) transfers, libcurl might erroneously use the read c ...

SUSE-SU-2022:3773-1
Security update for curl

SUSE-SU-2022:3770-1
Security update for curl

SUSE-SU-2022:3769-1
Security update for curl

RLSA-2023:0333
Moderate: curl security update
GHSA-grfr-78m7-q35q
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.
ELSA-2023-0333
ELSA-2023-0333: curl security update (MODERATE)

BDU:2022-07403
Уязвимость утилиты командной строки cURL, связанная с логической ошибкой повторно используемого дескриптора при обработке последующих HTTP-запросов PUT и POST, позволяющая нарушителю вызвать отказ в обслуживании или оказать иное воздействие на систему

SUSE-SU-2022:3785-1
Security update for curl

SUSE-SU-2022:3774-1
Security update for curl

SUSE-SU-2022:3772-1
Security update for curl

ROS-20221222-02
Множественные уязвимости cURL
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2022-32221 When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад |
![]() | CVE-2022-32221 When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST. | CVSS3: 4.8 | 1% Низкий | больше 2 лет назад |
![]() | CVE-2022-32221 When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад |
![]() | CVSS3: 9.8 | 1% Низкий | 12 месяцев назад | |
CVE-2022-32221 When doing HTTP(S) transfers, libcurl might erroneously use the read c ... | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
![]() | SUSE-SU-2022:3773-1 Security update for curl | 1% Низкий | больше 2 лет назад | |
![]() | SUSE-SU-2022:3770-1 Security update for curl | 1% Низкий | больше 2 лет назад | |
![]() | SUSE-SU-2022:3769-1 Security update for curl | 1% Низкий | больше 2 лет назад | |
![]() | RLSA-2023:0333 Moderate: curl security update | 1% Низкий | больше 2 лет назад | |
GHSA-grfr-78m7-q35q When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
ELSA-2023-0333 ELSA-2023-0333: curl security update (MODERATE) | больше 2 лет назад | |||
![]() | BDU:2022-07403 Уязвимость утилиты командной строки cURL, связанная с логической ошибкой повторно используемого дескриптора при обработке последующих HTTP-запросов PUT и POST, позволяющая нарушителю вызвать отказ в обслуживании или оказать иное воздействие на систему | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад |
![]() | SUSE-SU-2022:3785-1 Security update for curl | больше 2 лет назад | ||
![]() | SUSE-SU-2022:3774-1 Security update for curl | больше 2 лет назад | ||
![]() | SUSE-SU-2022:3772-1 Security update for curl | больше 2 лет назад | ||
![]() | ROS-20221222-02 Множественные уязвимости cURL | CVSS3: 9.8 | больше 2 лет назад |
Уязвимостей на страницу