VDB
ALSA-2022%3A6159
ALSA-2022%3A6159
PUBLISHED
The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP. Security Fix(es): * curl: HTTP compression denial of service (CVE-2022-32206) * curl: FTP-KRB bad message verification (CVE-2022-32208) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| AlmaLinux:8 | curl | 0, 0 |
| AlmaLinux:8 | libcurl | 0, 0 |
| AlmaLinux:8 | libcurl-devel | 0, 0 |
| AlmaLinux:8 | libcurl-minimal | 0, 0 |
Timeline
- Aug 24, 2022 CVE Published
- Aug 30, 2022 CVE Updated
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2022:6159 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-32206 third-party-advisory
- https://access.redhat.com/security/cve/CVE-2022-32208 third-party-advisory
- https://bugzilla.redhat.com/2099300 third-party-advisory
- https://bugzilla.redhat.com/2099306 third-party-advisory
- https://errata.almalinux.org/8/ALSA-2022-6159.html vendor-advisory