SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-32206

The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end…

MEDIUM 6.5EPSS 32.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 32.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
32.16% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-770
Affected
haxx/curl · fedoraproject/fedora · debian/debian linux · netapp/clustered data ontap · netapp/element software · netapp/hci management node · netapp/solidfire · netapp/bootstrap os · netapp/h300s firmware · netapp/h500s firmware · netapp/h700s firmware · netapp/h410s firmware · siemens/scalance sc622-2c firmware · siemens/scalance sc626-2c firmware · siemens/scalance sc632-2c firmware · siemens/scalance sc636-2c firmware · siemens/scalance sc642-2c firmware · siemens/scalance sc646-2c firmware · splunk/universal forwarder
Source
support@hackerone.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.