CVE-2022-27782: High severity haxx curl vulnerability
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However several TLS andSSH settings were left out from the configuration match checks making themmatch too easily.
Other sources
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27782?
CVE-2022-27782 is a vulnerability in libcurl that allows the reuse of a previously created connection even when a TLS or SSH-related option had been changed that should have prohibited reuse.
What is the severity of CVE-2022-27782?
The severity of CVE-2022-27782 is not stated in the provided information.
How does libcurl handle previously used connections?
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup.
Which versions of curl are affected by CVE-2022-27782?
Versions 7.64.0-4+deb10u6, 7.74.0-1.3+deb11u7, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-11, and 8.2.1-1 of curl on Debian are affected by CVE-2022-27782.
How can I fix CVE-2022-27782?
Apply the recommended patches or updates provided by Debian for curl versions 7.64.0-4+deb10u6, 7.74.0-1.3+deb11u7, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-11, and 8.2.1-1.