Information disclosure in cURL - CVE-2022-27779
Published: May 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to libcurl wrongly allows HTTP cookies to be set for Top Level Domains (TLDs) if the host name is provided with a trailing dot. As a result, an attacker can create cookie files that are later sent to a different and unrelated site or domain.
Affected software
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
IBM Engineering Requirements Management DOORS Next
Gentoo Linux
Amazon Linux AMI
PowerSC
Slackware Linux
Fedora
IBM Rational ClearCase
Splunk Universal Forwarder
Splunk Enterprise
curl
net-misc/curl
PowerScale OneFS
How to mitigate CVE-2022-27779
IBM Rational ClearCase - addressed in versions 9.0.1.14, 9.0.2.6, 9.1.0.3
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
curl - update to 7.82.0-5.fc36
net-misc/curl - update to 7.86.0
curl - update to 7.87.0-2
PowerScale OneFS - addressed in versions 9.1.0.26, 9.2.1.19, 9.4.0.10
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Slackware Linux update for curl
- Multiple vulnerabilities in IBM Rational ClearCase
- Multiple vulnerabilities in IBM PowerSC
- Gentoo update for curl
- Multiple vulnerabilities in Dell PowerScale OneFS
- Splunk Universal Forwarder update for third-party packages
- Multiple vulnerabilities in Dell Data Protection Central
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- Amazon Linux AMI update for curl
- Fedora 36 update for curl