SUSE-SU-2022:1657-1
Dashboard / Vulnerabilities / SUSE-SU-2022:1657-1
SUSE-SU-2022:1657-1
Summary: Security update for curl
Details: This update for curl fixes the following issues: - CVE-2022-27776: Fixed auth/cookie leak on redirect (bsc#1198766) - CVE-2022-27775: Fixed bad local IPv6 connection reuse (bsc#1198723) - CVE-2022-22576: Fixed OAUTH2 bearer bypass in connection re-use (bsc#1198614)
References: https://www.suse.com/support/update/announcement/2022/suse-su-20221657-1/, https://bugzilla.suse.com/1198614, https://bugzilla.suse.com/1198723, https://bugzilla.suse.com/1198766, https://www.suse.com/security/cve/CVE-2022-22576, https://www.suse.com/security/cve/CVE-2022-27775, https://www.suse.com/security/cve/CVE-2022-27776
Affected packages
Package
Name: curl
Purl: pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
