When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5197-1 | curl security update |
EUVD |
EUVD-2022-53413 | When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended. |
Ubuntu USN |
USN-5495-1 | curl vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-04-23T18:04:31.119Z
Reserved: 2022-06-01T00:00:00.000Z
Link: CVE-2022-32207
Updated: 2024-08-03T07:32:56.011Z
Status : Modified
Published: 2022-07-07T13:15:08.403
Modified: 2025-04-23T18:15:53.880
Link: CVE-2022-32207
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN