cbcvebase.
CVE-2022-35260
published 2022-12-05

CVE-2022-35260: curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould…

PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.76%
75.1th percentile
curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or similar, but circumstances might also cause different outcomes.If a malicious user can provide a custom netrc file to an application or otherwise affect its contents, this flaw could be used as denial-of-service.

Affected

20 ranges
VendorProductVersion rangeFixed in
applemacos< 12.6.312.6.3
applemacos_monterey
applemacos_ventura
debiancurl< curl 7.86.0-1 (bookworm)curl 7.86.0-1 (bookworm)
haxxcurl>= 0 < 7.86.0-17.86.0-1
haxxcurl>= 0 < 7.86.0-17.86.0-1
haxxcurl>= 0 < 7.86.0-17.86.0-1
haxxcurl>= 0 < 7.58.0-2ubuntu3.217.58.0-2ubuntu3.21
haxxcurl>= 0 < 7.68.0-1ubuntu2.147.68.0-1ubuntu2.14
haxxcurl>= 0 < 7.81.0-1ubuntu1.67.81.0-1ubuntu1.6
haxxcurl>= 7.84.0 < 7.86.07.86.0
httpsgithub.com_curl_curl
msrcazl3_tensorflow_2.11.1-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_tensorflow_2.11.1-2_on_cbl_mariner_2.0
splunkuniversal_forwarder
splunkuniversal_forwarder>= 8.2.0 < 8.2.128.2.12
splunkuniversal_forwarder>= 9.0.0 < 9.0.69.0.6

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.