SUSE-SU-2022:2813-1
Dashboard / Vulnerabilities / SUSE-SU-2022:2813-1
SUSE-SU-2022:2813-1
Summary: Security update for curl
Details: This update for curl fixes the following issues: - CVE-2022-27781: Fixed an issue where curl will get stuck in an infinite loop when trying to retrieve details about a TLS server's certificate chain (bnc#1199223). - CVE-2022-27782: Fixed an issue where TLS and SSH connections would be reused even when a related option had been changed (bsc#1199224). - CVE-2022-32206: Fixed an uncontrolled memory consumption issue caused by an unbounded number of compression layers (bsc#1200735). - CVE-2022-32208: Fixed an incorrect message verification issue when performing FTP transfers using krb5 (bsc#1200737).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20222813-1/, https://bugzilla.suse.com/1199223, https://bugzilla.suse.com/1199224, https://bugzilla.suse.com/1200735, https://bugzilla.suse.com/1200737, https://www.suse.com/security/cve/CVE-2022-27781, https://www.suse.com/security/cve/CVE-2022-27782, https://www.suse.com/security/cve/CVE-2022-32206, https://www.suse.com/security/cve/CVE-2022-32208
Affected packages
Package
Name: curl
Purl: pkg:rpm/suse/curl&distro=SUSE%20OpenStack%20Cloud%209
Affected ranges
Type: ECOSYSTEM
Events:
