QID 355051

Date Published: 2023-05-18

QID 355051: Amazon Linux Security Advisory for curl : AL2012-2022-375

Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-35252:
A vulnerability found in curl. This security flaw happens when curl is used to retrieve and parse cookies from an HTTP(S) server, where it accepts cookies using control codes (byte values below 32), and also when cookies that contain such control codes are later sent back to an HTTP(S) server, possibly causing the server to return a 400 response. This issue effectively allows a "sister site" to deny service to siblings and cause a denial of service attack. 2120718: CVE-2022-35252 curl: control code in cookie denial of service CVE-2022-32208:
A vulnerability was found in curl. This issue occurs because it mishandles message verification failures when curl does FTP transfers secured by krb5. This flaw makes it possible for a Man-in-the-middle attack to go unnoticed and allows data injection into the client. 2099306: CVE-2022-32208 curl: FTP-KRB bad message verification

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Administrators are advised to apply the appropriate software updates.
    Vendor References

    CVEs related to QID 355051

    Software Advisories
    Advisory ID Software Component Link
    AL2012-2022-375 Amazon Linux Bare Metal URL Logo docs.aws.amazon.com/AWSEC2/latest/UserGuide/install-updates.html