[FEDORA-2022-39688a779d] Fedora 35: curl

Severity Critical
Affected Packages 1
CVEs 4
  • url: use IDN decoded names for HSTS checks (CVE-2022-42916) - http_proxy: restore the protocol pointer on error (CVE-2022-42915) - netrc: replace XXXXX with Curl_get_line (CVE-2022-35260) - fix POST following PUT confusion (CVE-2022-32221)
Package Affected Version
pkg:rpm/fedora/curl?distro=fedora-35 < 7.79.1.7.fc35
Source # ID Name URL
Bugzilla 2137780 Bug #2137780 - CVE-2022-32221 curl: POST following PUT confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2137780
Bugzilla 2138111 Bug #2138111 - CVE-2022-42915 curl: HTTP proxy double-free [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2138111
Bugzilla 2137769 Bug #2137769 - CVE-2022-42916 curl: HSTS bypass via IDN [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2137769
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/curl?distro=fedora-35 fedora curl < 7.79.1.7.fc35 fedora-35
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...