#VU64682 Resource exhaustion in cURL


Published: 2022-06-27

Vulnerability identifier: #VU64682

Vulnerability risk: Medium

CVSSv3.1:

CVE-ID: CVE-2022-32206

CWE-ID:

Exploitation vector: Network

Exploit availability:

Vulnerable software:
cURL
Client/Desktop applications / Other client software

Vendor: curl.haxx.se

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insecure processing of compressed HTTP responses. A malicious server can send a specially crafted HTTP response to curl and perform a denial of service attack by forcing curl to spend enormous amounts of allocated heap memory, or trying to and returning out of memory errors.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

cURL: 7.57.0 - 7.83.1


Fixed software versions

CPE

External links
http://curl.haxx.se/docs/CVE-2022-32206.html


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability