First published: Wed Aug 24 2022(Updated: )
The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.<br>Security Fix(es):<br><li> curl: HTTP compression denial of service (CVE-2022-32206)</li> <li> curl: FTP-KRB bad message verification (CVE-2022-32208)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/curl | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/curl | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/curl-debuginfo | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/curl-debuginfo | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/curl-debugsource | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/curl-debugsource | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/curl-minimal-debuginfo | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/curl-minimal-debuginfo | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl-debuginfo | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl-debuginfo | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl-devel | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl-devel | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl-minimal | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl-minimal | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl-minimal-debuginfo | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl-minimal-debuginfo | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/curl | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/curl-debuginfo | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/curl-debugsource | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/curl-minimal-debuginfo | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl-debuginfo | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl-devel | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl-minimal | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/libcurl-minimal-debuginfo | <7.61.1-22.el8_6.4 | 7.61.1-22.el8_6.4 |
redhat/curl | <7.61.1-22.el8_6.4.aa | 7.61.1-22.el8_6.4.aa |
redhat/curl-debuginfo | <7.61.1-22.el8_6.4.aa | 7.61.1-22.el8_6.4.aa |
redhat/curl-debugsource | <7.61.1-22.el8_6.4.aa | 7.61.1-22.el8_6.4.aa |
redhat/curl-minimal-debuginfo | <7.61.1-22.el8_6.4.aa | 7.61.1-22.el8_6.4.aa |
redhat/libcurl | <7.61.1-22.el8_6.4.aa | 7.61.1-22.el8_6.4.aa |
redhat/libcurl-debuginfo | <7.61.1-22.el8_6.4.aa | 7.61.1-22.el8_6.4.aa |
redhat/libcurl-devel | <7.61.1-22.el8_6.4.aa | 7.61.1-22.el8_6.4.aa |
redhat/libcurl-minimal | <7.61.1-22.el8_6.4.aa | 7.61.1-22.el8_6.4.aa |
redhat/libcurl-minimal-debuginfo | <7.61.1-22.el8_6.4.aa | 7.61.1-22.el8_6.4.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2022:6159 addresses a denial of service vulnerability in curl related to HTTP compression and a bad message vulnerability in FTP with Kerberos.
To fix RHSA-2022:6159, upgrade the curl package to version 7.61.1-22.el8_6.4 or later.
The severity of RHSA-2022:6159 is classified as Important due to its potential impact on service availability.
The affected packages in RHSA-2022:6159 include curl, libcurl, and their respective debug and development packages.
Updates available for RHSA-2022:6159 include curl packages specifically remediated to version 7.61.1-22.el8_6.4.