Oval Definition:oval:org.opensuse.security:def:202235252
Revision Date:2023-06-22Version:1
Title:CVE-2022-35252
Description:

When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2022-35252
SUSE CVE-2022-35252
SUSE-CU-2022:2027-1
SUSE-CU-2022:2028-1
SUSE-CU-2022:2030-1
SUSE-CU-2022:2031-1
SUSE-CU-2022:2032-1
SUSE-CU-2022:2033-1
SUSE-CU-2022:2034-1
SUSE-CU-2022:2035-1
SUSE-CU-2022:2036-1
SUSE-CU-2022:2037-1
SUSE-CU-2022:2038-1
SUSE-CU-2022:2039-1
SUSE-CU-2022:2040-1
SUSE-CU-2022:2041-1
SUSE-CU-2022:2042-1
SUSE-CU-2022:2043-1
SUSE-CU-2022:2047-1
SUSE-CU-2022:2049-1
SUSE-CU-2022:2050-1
SUSE-CU-2022:2051-1
SUSE-CU-2022:2053-1
SUSE-CU-2022:2054-1
SUSE-CU-2022:2055-1
SUSE-CU-2022:2056-1
SUSE-CU-2022:2057-1
SUSE-CU-2022:2058-1
SUSE-CU-2022:2059-1
SUSE-CU-2022:2062-1
SUSE-CU-2022:2063-1
SUSE-CU-2022:2064-1
SUSE-CU-2022:2066-1
SUSE-CU-2022:2067-1
SUSE-CU-2022:2068-1
SUSE-CU-2022:2078-1
SUSE-CU-2022:2082-1
SUSE-CU-2022:2083-1
SUSE-CU-2022:2084-1
SUSE-CU-2022:2085-1
SUSE-CU-2022:2086-1
SUSE-CU-2022:2087-1
SUSE-CU-2022:2088-1
SUSE-CU-2022:2089-1
SUSE-CU-2022:2090-1
SUSE-CU-2022:2091-1
SUSE-CU-2022:2092-1
SUSE-CU-2022:2093-1
SUSE-CU-2022:2094-1
SUSE-CU-2022:2095-1
SUSE-CU-2022:2123-1
SUSE-CU-2022:2124-1
SUSE-CU-2022:2125-1
SUSE-CU-2022:2126-1
SUSE-CU-2022:2149-1
SUSE-CU-2022:2229-1
SUSE-CU-2022:2258-1
SUSE-CU-2022:2260-1
SUSE-CU-2022:2262-1
SUSE-CU-2022:2264-1
SUSE-CU-2022:2266-1
SUSE-CU-2022:2268-1
SUSE-CU-2022:2270-1
SUSE-CU-2022:2272-1
SUSE-CU-2022:2274-1
SUSE-CU-2022:2276-1
SUSE-CU-2022:2278-1
SUSE-CU-2022:2280-1
SUSE-CU-2022:2282-1
SUSE-CU-2022:2561-1
SUSE-CU-2022:2655-1
SUSE-CU-2022:2732-1
SUSE-CU-2022:2738-1
SUSE-CU-2022:2739-1
SUSE-CU-2022:3263-1
SUSE-CU-2022:3264-1
SUSE-CU-2022:3265-1
SUSE-CU-2022:3269-1
SUSE-CU-2023:1103-1
SUSE-CU-2023:1104-1
SUSE-CU-2023:1105-1
SUSE-CU-2023:1261-1
SUSE-CU-2023:1262-1
SUSE-CU-2023:1338-1
SUSE-CU-2023:321-1
SUSE-CU-2023:322-1
SUSE-CU-2023:323-1
SUSE-CU-2023:324-1
SUSE-IU-2022:1081-1
SUSE-IU-2022:1082-1
SUSE-IU-2022:1083-1
SUSE-IU-2022:1084-1
SUSE-IU-2022:1110-1
SUSE-IU-2022:1118-1
SUSE-SU-2022:3003-1
SUSE-SU-2022:3004-1
SUSE-SU-2022:3005-1
SUSE-SU-2022:3772-1
SUSE-SU-2022:3774-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Performance Computing 12 SP5
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Module for Basesystem 15 SP5
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP5
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND Package Information
  • curl is affected
  • OR libcurl4 is affected
  • OR libcurl4-32bit is affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND curl is affected
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • AND
  • curl is affected
  • OR libcurl4 is affected
  • OR libcurl4-32bit is affected
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
  • AND Package Information
  • curl is affected
  • OR libcurl-devel is affected
  • OR libcurl4 is affected
  • OR libcurl4-32bit is affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND Package Information
  • curl-8.0.1-150400.5.23.1 is installed
  • OR libcurl-devel-8.0.1-150400.5.23.1 is installed
  • OR libcurl4-8.0.1-150400.5.23.1 is installed
  • OR libcurl4-32bit-8.0.1-150400.5.23.1 is installed
  • BACK