Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2022-27781
HistoryJun 02, 2022 - 2:15 p.m.

CVE-2022-27781

2022-06-0214:15:44
Debian Security Bug Tracker
security-tracker.debian.org
56
libcurl
curlopt_certinfo
vulnerability
nss
server certificate

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

56.2%

libcurl provides the CURLOPT_CERTINFO option to allow applications torequest details to be returned about a serverโ€™s certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.

OSVersionArchitecturePackageVersionFilename
Debian12allcurl<ย 7.83.1-1curl_7.83.1-1_all.deb
Debian11allcurl<ย 7.74.0-1.3+deb11u2curl_7.74.0-1.3+deb11u2_all.deb
Debian999allcurl<ย 7.83.1-1curl_7.83.1-1_all.deb
Debian13allcurl<ย 7.83.1-1curl_7.83.1-1_all.deb

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

56.2%