TROYANOSYVIRUS
Back to CVEs

CVE-2022-32221

CRITICAL
9.8

Description

When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published12/5/2022
Last Modified2/13/2026
Sourcenvd
Honeypot Sightings0

Affected Products

apple:macosdebian:debian_linuxhaxx:curlnetapp:clustered_data_ontapnetapp:h300snetapp:h300s_firmwarenetapp:h410snetapp:h410s_firmwarenetapp:h500snetapp:h500s_firmwarenetapp:h700snetapp:h700s_firmwaresplunk:universal_forwarder

Weaknesses (CWE)

CWE-200CWE-668

References

http://seclists.org/fulldisclosure/2023/Jan/19(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2023/Jan/20(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2023/05/17/4(af854a3a-2127-422b-91ae-364da2661108)
https://hackerone.com/reports/1704017(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/202212-01(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20230110-0006/(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20230208-0002/(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT213604(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT213605(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2023/dsa-5330(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.