HIGH 8.1 Microsoft
CVE-2022-42915
curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL it sets up the connection to the remote server by issuing a CONNECT request to the proxy and then tunnels the rest of the protocol through. An HTTP proxy might refuse this request (HTTP proxies often only allow outgoing connections to specific port numbers like 443 for HTTPS) and instead return a non-200 status code to the client. Due to flaws in the error/cleanup handling this could trigger a double free in curl if one of the following schemes were used in the URL for the transfer: dict gopher gophers ldap ldaps rtmp rtmps or telnet. The earliest affected version is 7.77.0.
Microsoft Security Update 2022-Oct: curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL it sets up the connection to the remote server by issuing a CONNECT request to the proxy and then tunnels the rest of the protocol through. An HTTP proxy might refuse this request (HTTP proxies often only allow outgoing connections to specific port numbers like 443 for HTTPS) and instead return a non-200 status code to the client. Due to flaws in the error/cleanup handling this could trigger a double free in curl if one of the following schemes were used in the URL for the transfer: dict gopher gophers ldap ldaps rtmp rtmps or telnet. The earliest affected version is 7.77.0.
Affected Products
- azl3 tensorflow 2.11.1-1 on Azure Linux 3.0
- cm1 curl 7.86.0-1 on CBL Mariner 1.0
- cbl2 curl 7.86.0-1 on CBL Mariner 2.0
- azl3 tensorflow 2.16.1-1 on Azure Linux 3.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-42915
- https://nvd.nist.gov/vuln/detail/CVE-2022-42915
This high severity vulnerability with a CVSS score of 8.1 was published on 2022-10-11 via Microsoft. Affected: azl3 tensorflow 2.11.1-1 on Azure Linux 3.0, cm1 curl 7.86.0-1 on CBL Mariner 1.0, cbl2 curl 7.86.0-1 on CBL Mariner 2.0 and 1 more.
vulnfeed aggregates 9119 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.