cbcvebase.
CVE-2022-43552
published 2023-02-09

CVE-2022-43552: A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies…

PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
2.51%
82.7th percentile
A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
applemacos>= 13.0 < 13.313.3
applemacos_ventura
debiancurl< curl 7.86.0-3 (bookworm)curl 7.86.0-3 (bookworm)
haxxcurl< 7.87.07.87.0
haxxcurl>= 0 < 7.74.0-1.3+deb11u57.74.0-1.3+deb11u5
haxxcurl>= 0 < 7.86.0-37.86.0-3
haxxcurl>= 0 < 7.86.0-37.86.0-3
haxxcurl>= 0 < 7.86.0-37.86.0-3
haxxcurl>= 0 < 7.58.0-2ubuntu3.227.58.0-2ubuntu3.22
haxxcurl>= 0 < 7.68.0-1ubuntu2.157.68.0-1ubuntu2.15
haxxcurl>= 0 < 7.81.0-1ubuntu1.77.81.0-1ubuntu1.7
haxxcurl>= 0 < 7.35.0-1ubuntu2.20+esm147.35.0-1ubuntu2.20+esm14
haxxcurl>= 0 < 7.47.0-1ubuntu2.19+esm77.47.0-1ubuntu2.19+esm7
httpsgithub.com_curl_curl
msrcazl3_cmake_3.21.4-10_on_azure_linux_3.0
msrcazl3_cmake_3.28.2-1_on_azure_linux_3.0
msrcazl3_rust_1.75.0-14_on_azure_linux_3.0
msrcazl3_rust_1.86.0-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.11.1-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-1_on_azure_linux_3.0
msrccbl2_cmake_3.21.4-13_on_cbl_mariner_2.0
msrccbl2_curl_7.86.0-3_on_cbl_mariner_2.0
msrccbl2_mysql_8.0.33-1_on_cbl_mariner_2.0
msrccbl2_rust_1.72.0-2_on_cbl_mariner_2.0
msrccbl2_tensorflow_2.11.1-2_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.