Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2022-32206
HistoryJul 07, 2022 - 1:15 p.m.

CVE-2022-32206

2022-07-0713:15:08
Alpine Linux Development Team
security.alpinelinux.org
25

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

8.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.1%

curl < 7.84.0 supports โ€œchainedโ€ HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable โ€œlinksโ€ in this โ€œdecompression chainโ€ was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a โ€œmalloc bombโ€, makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

8.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.1%