Improper control of a resource through its lifetime in cURL - CVE-2022-27778
Published: May 11, 2022
Vulnerability identifier: #VU63004
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-27778
CWE-ID: CWE-664
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to delete files on the system.
The vulnerability exists in the curl command line tool when --no-clobber is used together with --remove-on-error. A remote attacker can trick the victim to connect to a malicious server and force the command line tool to remove unexpected files.
Affected software
cURL
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
IBM Engineering Requirements Management DOORS Next
PowerSC
Oracle Solaris
Slackware Linux
MySQL Server
IBM Rational ClearCase
Splunk Universal Forwarder
Splunk Enterprise
Dell EMC Storage Monitoring and Reporting (SMR)
PowerScale OneFS
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
IBM Engineering Requirements Management DOORS Next
PowerSC
Oracle Solaris
Slackware Linux
MySQL Server
IBM Rational ClearCase
Splunk Universal Forwarder
Splunk Enterprise
Dell EMC Storage Monitoring and Reporting (SMR)
PowerScale OneFS
How to mitigate CVE-2022-27778
Install updates from vendor's website.
cURL - update to 7.83.1
IBM Rational ClearCase - addressed in versions 9.0.1.14, 9.0.2.6, 9.1.0.3
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
PowerScale OneFS - addressed in versions 9.1.0.26, 9.2.1.19, 9.4.0.10
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM Rational ClearCase - addressed in versions 9.0.1.14, 9.0.2.6, 9.1.0.3
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
PowerScale OneFS - addressed in versions 9.1.0.26, 9.2.1.19, 9.4.0.10
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Slackware Linux update for curl
- Multiple vulnerabilities in MySQL Server
- Multiple vulnerabilities in IBM Rational ClearCase
- Multiple vulnerabilities in IBM PowerSC
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell PowerScale OneFS
- Multiple vulnerabilities in Oracle Solaris
- Splunk Universal Forwarder update for third-party packages
- Multiple vulnerabilities in Dell Data Protection Central
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA