When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
[
{
"vendor": "n/a",
"product": "https://github.com/curl/curl",
"versions": [
{
"version": "Fixed in 7.84.0",
"status": "affected"
}
]
}
]
seclists.org/fulldisclosure/2022/Oct/28
seclists.org/fulldisclosure/2022/Oct/41
hackerone.com/reports/1590071
lists.debian.org/debian-lts-announce/2022/08/msg00017.html
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/
security.gentoo.org/glsa/202212-01
security.netapp.com/advisory/ntap-20220915-0003/
support.apple.com/kb/HT213488
www.debian.org/security/2022/dsa-5197