Site icon 지락문화예술공작단

USN-5499-1: curl vulnerabilities

USN-5499-1: curl vulnerabilities

Florian Kohnhuser discovered that curl incorrectly handled returning a
TLS server’s certificate chain details. A remote attacker could possibly
use this issue to cause curl to stop responding, resulting in a denial of
service. (CVE-2022-27781)

Harry Sintonen discovered that curl incorrectly handled certain FTP-KRB
messages. An attacker could possibly use this to perform a
machine-in-the-middle attack. (CVE-2022-32208)
Source: USN-5499-1: curl vulnerabilities

Exit mobile version