QID 355059
Date Published: 2023-05-18
QID 355059: Amazon Linux Security Advisory for curl : AL2012-2023-383
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-32221:
A vulnerability was found in curl. The issue occurs when doing HTTP(S) transfers, where curl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set if it previously used the same handle to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request.
2135411: CVE-2022-32221 curl: POST following PUT confusion
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
CVEs related to QID 355059
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2023-383 | Amazon Linux Bare Metal |
|