Mageia 2022-0250: curl security update
Summary
Set-Cookie denial of service. (CVE-2022-32205)
HTTP compression denial of service. (CVE-2022-32206)
Unpreserved file permissions. (CVE-2022-32207)
FTP-KRB bad message verification. (CVE-2022-32208)
References
- https://bugs.mageia.org/show_bug.cgi?id=30582
- https://curl.se/docs/CVE-2022-32205.html
- https://curl.se/docs/CVE-2022-32206.html
- https://curl.se/docs/CVE-2022-32207.html
- https://curl.se/docs/CVE-2022-32208.html
- https://ubuntu.com/security/notices/USN-5495-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32205
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32206
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32207
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32208
Resolution
MGASA-2022-0250 - Updated curl packages fix security vulnerability
SRPMS
- 8/core/curl-7.74.0-1.7.mga8