Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 8: 2022-0483 Critical: Curl HSTS Bypass And Use-After-Free

mageia
Calendar Grey December 30, 2022
Dist Mageia Esm H88
Mageia 2022-0491 resolves significant issues in OpenSSL. It's essential to ensure your system is updated with the most recent security patches.
Another HSTS bypass via IDN

Summary

Another HSTS bypass via IDN. (CVE-2022-43551) HTTP Proxy deny use-after-free. (CVE-2022-43552)

References

- https://bugs.mageia.org/show_bug.cgi?id=31306

- https://curl.se/docs/CVE-2022-43551.html

- https://curl.se/docs/CVE-2022-43552.html

-

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/TVWZW5CNSJ7UYAF2BGSYAWAEXDJYUBHA/

- https://www.cve.org/CVERecord?id=CVE-2022-43551

- https://www.cve.org/CVERecord?id=CVE-2022-43552

Resolution

SRPMS

- 8/core/curl-7.74.0-1.10.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 30 Dec 2022
URL: https://advisories.mageia.org/MGASA-2022-0483.html
Type: security
CVE: CVE-2022-43551, CVE-2022-43552

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here