CVE-2022-27778 log

Source
Severity Medium
Remote Unknown
Type Unknown
Description
If curl adds a number to not "clobber" the output and an error occurs during transfer, the remove on error logic would remove the *original* file name without the added number.
Group Package Affected Fixed Severity Status Ticket
AVG-2706 curl 7.83.0-1 7.83.1-1 Medium Fixed
References
https://seclists.org/oss-sec/2022/q2/92
https://curl.se/docs/CVE-2022-27778.html
https://github.com/curl/curl/commit/8c7ee9083d0d71
Notes
Affected versions: curl 7.83.0
Not affected versions: curl < 7.83.0 and curl >= 7.83.1