CVE-2022-32208: Input Validation
A vulnerability was found in curl. This issue occurs because it mishandles message verification failures when curl does FTP transfers secured by krb5. This flaw makes it possible for a Man-in-the-middle attack to go unnoticed and allows data injection into the client.
Other sources
Accelerate Framework. A memory consumption issue was addressed with improved memory handling.
— Apple
APFS. An access issue was addressed with improved access restrictions.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleAVD. A memory corruption issue was addressed with improved state management.
— Apple
AppleAVD. This issue was addressed with improved checks.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.86.0-2.el8 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.86.0-2.el7 - Upgrade
Upgrade
redhat/curlto a version that resolves this vulnerability.Fixed in 0:7.61.1-22.el8_6.4 - Upgrade
Upgrade
redhat/curlto a version that resolves this vulnerability.Fixed in 0:7.76.1-14.el9_0.5 - Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 7.64.0-4+deb10u7Fixed in 7.74.0-1.3+deb11u9Fixed in 7.74.0-1.3+deb11u10Fixed in 7.88.1-10+deb12u3Fixed in 7.88.1-10+deb12u4Fixed in 8.4.0-2 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13 - Upgrade
Upgrade
redhat/curlto a version that resolves this vulnerability.Fixed in 7.84.0 - Upgrade
Upgrade
curlto a version that resolves this vulnerability.Fixed in 7.84.0 - Configuration
Remove the additional entitlements referenced by the issue that allowed improper access; this was addressed by removing additional entitlements.
third-party apps sandbox entitlements = removed - Compensating control
Harden network communications to reduce exposure to Man-in-the-Middle attacks (the vulnerability allows MITM to go unnoticed and inject data to the client) until the curl update to 7.84.0 is applied.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-42795
- CVE-2022-48577
- CVE-2022-32858
- CVE-2022-32898
- CVE-2022-32899
- CVE-2022-46721
- CVE-2022-47915
- CVE-2022-47965
- CVE-2022-32889
- CVE-2022-32907
- CVE-2022-32827
- CVE-2022-32877
- CVE-2022-42789
- CVE-2022-42825
- CVE-2022-46722
- CVE-2022-32902
- CVE-2022-32904
- CVE-2022-32890
- CVE-2022-42796
- CVE-2022-42798
- CVE-2022-32940
- CVE-2022-42816
- CVE-2022-42821
- CVE-2022-42860
- CVE-2022-42819
- CVE-2022-42813
- CVE-2022-26730
- CVE-2022-32945
- CVE-2022-42838
- CVE-2022-48683
- CVE-2022-22663
- CVE-2022-32867
- CVE-2022-32205
- CVE-2022-32206
- CVE-2022-32207
- CVE-2022-32208
- CVE-2022-42814
- CVE-2022-32865
- CVE-2022-32915
- CVE-2022-32928
- CVE-2022-22643
- CVE-2022-32935
- CVE-2022-42788
- CVE-2022-48504
- CVE-2022-32905
- CVE-2022-42833
- CVE-2022-32947
- CVE-2022-42809
- CVE-2022-3437
- CVE-2022-32849
- CVE-2022-32913
- CVE-2022-32809
- CVE-2022-1622
- CVE-2022-32936
- CVE-2022-42820
- CVE-2022-42806
- CVE-2022-32864
- CVE-2022-32866
- CVE-2022-32911
- CVE-2022-32924
- CVE-2022-32914
- CVE-2022-42808
- CVE-2022-32944
- CVE-2022-42803
- CVE-2022-32926
- CVE-2022-42801
- CVE-2022-46712
- CVE-2022-42815
- CVE-2022-42834
- CVE-2022-46707
- CVE-2022-32883
- CVE-2022-32908
- CVE-2022-42810
- CVE-2021-39537
- CVE-2022-29458
- CVE-2022-42818
- CVE-2022-32879
- CVE-2022-32895
- CVE-2022-46713
- CVE-2022-42807
- CVE-2022-32918
- CVE-2022-42829
- CVE-2022-42830
- CVE-2022-42831
- CVE-2022-42832
- CVE-2022-32941
- CVE-2022-28739
- CVE-2022-32881
- CVE-2022-32862
- CVE-2022-32931
- CVE-2022-42811
- CVE-2022-42793
- CVE-2022-32876
- CVE-2022-32938
- CVE-2022-42790
- CVE-2022-32870
- CVE-2022-32934
- CVE-2022-42791
- CVE-2021-36690
- CVE-2022-48505
- CVE-2022-26699
- CVE-2022-0261
- CVE-2022-0318
- CVE-2022-0319
- CVE-2022-0351
- CVE-2022-0359
- CVE-2022-0361
- CVE-2022-0368
- CVE-2022-0392
- CVE-2022-0554
- CVE-2022-0572
- CVE-2022-0629
- CVE-2022-0685
- CVE-2022-0696
- CVE-2022-0714
- CVE-2022-0729
- CVE-2022-0943
- CVE-2022-1381
- CVE-2022-1420
- CVE-2022-1725
- CVE-2022-1616
- CVE-2022-1619
- CVE-2022-1620
- CVE-2022-1621
- CVE-2022-1629
- CVE-2022-1674
- CVE-2022-1733
- CVE-2022-1735
- CVE-2022-1769
- CVE-2022-1927
- CVE-2022-1942
- CVE-2022-1968
- CVE-2022-1851
- CVE-2022-1897
- CVE-2022-1898
- CVE-2022-1720
- CVE-2022-2000
- CVE-2022-2042
- CVE-2022-2124
- CVE-2022-2125
- CVE-2022-2126
- CVE-2022-42828
- CVE-2022-32875
- CVE-2022-42826
- CVE-2022-32886
- CVE-2022-32888
- CVE-2022-32912
- CVE-2022-42799
- CVE-2022-42823
- CVE-2022-42824
- CVE-2022-32923
- CVE-2022-32922
- CVE-2022-32892
- CVE-2022-32833
- CVE-2022-46709
- CVE-2022-37434
- CVE-2022-42800
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-32208.
What is the severity of CVE-2022-32208?
The severity of CVE-2022-32208 is medium with a CVSS score of 5.3.
How does CVE-2022-32208 occur?
CVE-2022-32208 occurs because curl mishandles message verification failures when doing FTP transfers secured by krb5, allowing a Man-in-the-middle attack and data injection into the client.
Which software is affected by CVE-2022-32208?
The software affected by CVE-2022-32208 includes curl version 7.84.0, jbcs-httpd24-curl versions 0:7.86.0-2.el8 and 0:7.86.0-2.el7, curl version 7.61.1-22.el8_6, curl version 7.76.1-14.el9_0, Apple macOS Ventura version up to 13, and curl versions 7.64.0-4+deb10u6, 7.74.0-1.3+deb11u7, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-11, and 8.2.1-1.
How can I fix CVE-2022-32208?
To fix CVE-2022-32208, update to curl version 7.84.0 or later.