Vulnerability Name: | CVE-2022-43552 (CCN-242799) | ||||||||||||
Assigned: | 2022-12-21 | ||||||||||||
Published: | 2022-12-21 | ||||||||||||
Updated: | 2023-03-28 | ||||||||||||
Summary: | cURL libcurl is vulnerable to a denial of service, caused by a use-after-free flaw when using an HTTP proxy. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition. | ||||||||||||
CVSS v3 Severity: | 5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.4 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:C)
| ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-43552 Source: support@hackerone.com Type: UNKNOWN support@hackerone.com Source: CCN Type: Project curl Security Advisory, December 21 2022 CVE-2022-43552: HTTP Proxy deny use-after-free Source: XF Type: UNKNOWN curl-cve202243552-dos(242799) Source: support@hackerone.com Type: Exploit, Issue Tracking, Third Party Advisory support@hackerone.com Source: support@hackerone.com Type: Vendor Advisory support@hackerone.com Source: support@hackerone.com Type: UNKNOWN support@hackerone.com Source: CCN Type: IBM Security Bulletin 6857685 (QRadar WinCollect Agent) libcurl as used by IBM QRadar Wincollect agent is vulnerable to denial of service (CVE-2022-43552, CVE-2022-43551) Source: CCN Type: IBM Security Bulletin 6965816 (Spectrum Protect Plus) Vulnerabilities in Node.js, libcurl, Golang Go, Jetty, Guava, Netty, OpenSSL, Linux kernel may affect IBM Spectrum Protect Plus Source: CCN Type: IBM Security Bulletin 6986573 (Safer Payments) Multiple publicly disclosed Libcurl vulnerabilities affect IBM Safer Payments Source: CCN Type: IBM Security Bulletin 7004197 (MQ Operator) IBM MQ Operator and Queue manager container images are vulnerable to multiple vulnerabilities from Kubernetes, curl and systemd Source: CCN Type: IBM Security Bulletin 7004263 (PowerSC) Multiple vulnerabilities in Curl affect PowerSC Source: CCN Type: IBM Security Bulletin 7005589 (Spectrum Protect Plus) Vulnerabilities in Apache Commons, Tomcat, Go, libcurl, OpenSSL, Python, Node.js, and Linux can affect IBM Spectrum Protect Plus. Source: CCN Type: IBM Security Bulletin 7008409 (AIX) Multiple vulnerabilities in cURL libcurl affect AIX Source: CCN Type: IBM Security Bulletin 7012459 (Spectrum Copy Data Management) Vulnerabilities in Golang, Python, postgresql, cURL libcurl might affect IBM Spectrum Copy Data Management Source: CCN Type: IBM Security Bulletin 7014659 (Cloud Transformation Advisor) IBM Cloud Transformation Advisor is vulnerable to multiple vulnerabilities | ||||||||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |