CVE-2022-27778 - log back

CVE-2022-27778 edited at 11 May 2022 11:19:49
Severity
- Unknown
+ Medium
Description
+ If curl adds a number to not "clobber" the output and an error occurs during transfer, the remove on error logic would remove the *original* file name without the added number.
References
+ https://seclists.org/oss-sec/2022/q2/92
+ https://curl.se/docs/CVE-2022-27778.html
+ https://github.com/curl/curl/commit/8c7ee9083d0d71
Notes
+ Affected versions: curl 7.83.0
+ Not affected versions: curl < 7.83.0 and curl >= 7.83.1
CVE-2022-27778 created at 11 May 2022 10:34:34
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes