CVE-2022-35252: Input Validation
A vulnerability found in curl. This security flaw happens when curl is used to retrieve and parse cookies from an HTTP(S) server, where it accepts cookies using control codes (byte values below 32), and also when cookies that contain such control codes are later sent back to an HTTP(S) server, possibly causing the server to return a 400 response. This issue effectively allows a "sister site" to deny service to siblings and cause a denial of service attack.
Other sources
Accounts. This issue was addressed with improved data protection.
— Apple
AMD. A memory corruption issue was addressed with improved input validation.
— Apple
AMD. An out-of-bounds write issue was addressed with improved input validation.
— Apple
AppleMobileFileIntegrity. This issue was addressed by enabling hardened runtime.
— Apple
Bluetooth. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-23499
- CVE-2022-35252
- CVE-2023-23513
- CVE-2023-23516
- CVE-2022-42834
- CVE-2023-23497
- CVE-2023-23505
- CVE-2023-27931
- CVE-2023-23518
- CVE-2023-23517
- CVE-2023-23508
- CVE-2022-42915
- CVE-2022-42916
- CVE-2022-32221
- CVE-2022-35260
- CVE-2023-23493
- CVE-2022-32915
- CVE-2023-23507
- CVE-2023-23504
- CVE-2023-23502
- CVE-2023-23511
- CVE-2022-42843
- CVE-2022-42858
- CVE-2022-42847
- CVE-2022-42865
- CVE-2022-42854
- CVE-2022-42853
- CVE-2022-42859
- CVE-2022-32942
- CVE-2022-46720
- CVE-2022-46710
- CVE-2022-46693
- CVE-2022-42864
- CVE-2022-46690
- CVE-2022-46697
- CVE-2022-42837
- CVE-2022-46689
- CVE-2022-46701
- CVE-2022-42842
- CVE-2022-42861
- CVE-2022-42845
- CVE-2022-48618
- CVE-2022-42839
- CVE-2022-46716
- CVE-2022-46704
- CVE-2022-32943
- CVE-2022-42840
- CVE-2022-42855
- CVE-2022-42862
- CVE-2022-24836
- CVE-2022-29181
- CVE-2022-46695
- CVE-2022-46718
- CVE-2022-46703
- CVE-2022-42866
- CVE-2022-32919
- CVE-2022-46725
- CVE-2022-46705
- CVE-2022-42867
- CVE-2022-46691
- CVE-2022-46692
- CVE-2022-42852
- CVE-2022-46696
- CVE-2022-46700
- CVE-2022-46698
- CVE-2022-46699
- CVE-2022-42863
- CVE-2022-42856
- CVE-2022-42841
- CVE-2022-43454
- CVE-2022-48610
Frequently Asked Questions
What is the vulnerability ID for this security flaw?
The vulnerability ID for this security flaw is CVE-2022-35252.
What is the severity of CVE-2022-35252?
The severity of CVE-2022-35252 is low with a CVSS score of 3.1.
Which software versions are affected by CVE-2022-35252?
The affected software versions are curl 7.85.0, jbcs-httpd24-curl 0:7.86.0-2.el8, jbcs-httpd24-curl 0:7.86.0-2.el7, curl 0:7.61.1-30.el8, curl 0:7.76.1-23.el9, macOS Big Sur 11.7.3, and macOS Monterey 12.6.3.
How can I fix the vulnerability?
To fix the vulnerability, update curl to version 7.85.0 or higher.
Where can I find more information about CVE-2022-35252?
You can find more information about CVE-2022-35252 at the following references: [Link 1](https://support.apple.com/en-us/HT213603), [Link 2](https://support.apple.com/en-us/HT213604), [Link 3](https://curl.se/docs/CVE-2022-35252.html).