CVE-2022-27778 log
Source |
|
Severity | Medium |
Remote | Unknown |
Type | Unknown |
Description | If curl adds a number to not "clobber" the output and an error occurs during transfer, the remove on error logic would remove the *original* file name without the added number. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-2706 | curl | 7.83.0-1 | 7.83.1-1 | Medium | Fixed |
References |
---|
https://seclists.org/oss-sec/2022/q2/92 https://curl.se/docs/CVE-2022-27778.html https://github.com/curl/curl/commit/8c7ee9083d0d71 |
Notes |
---|
Affected versions: curl 7.83.0 Not affected versions: curl < 7.83.0 and curl >= 7.83.1 |