CVE-2022-35260: Medium severity macos vulnerability
curl can be told to parse a .netrc file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or similar, but circumstances might also cause different outcomes.If a malicious user can provide a custom netrc file to an application or otherwise affect its contents, this flaw could be used as denial-of-service.
Other sources
curl. Multiple issues were addressed by updating to curl version 7.86.0.
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-23499
- CVE-2022-42915
- CVE-2022-42916
- CVE-2022-32221
- CVE-2022-35260
- CVE-2022-35252
- CVE-2023-23513
- CVE-2023-23493
- CVE-2022-32915
- CVE-2023-23507
- CVE-2023-23516
- CVE-2023-23504
- CVE-2023-23502
- CVE-2022-42834
- CVE-2023-23497
- CVE-2023-23505
- CVE-2023-27931
- CVE-2023-23511
- CVE-2023-23518
- CVE-2023-23517
- CVE-2023-23508
- CVE-2023-32438
- CVE-2023-23520
- CVE-2023-23539
- CVE-2023-41990
- CVE-2023-23530
- CVE-2023-23531
- CVE-2023-23519
- CVE-2023-23500
- CVE-2023-23506
- CVE-2023-23498
- CVE-2023-23503
- CVE-2023-28208
- CVE-2023-23510
- CVE-2023-23512
- CVE-2022-3705
- CVE-2023-32393
- CVE-2023-23496
- CVE-2023-23501
- CVE-2022-0108
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-35260.
What is the severity of CVE-2022-35260?
The severity of CVE-2022-35260 is not specified.
Which software versions are affected by CVE-2022-35260?
CVE-2022-35260 affects macOS Monterey version up to 12.6.3 and macOS Ventura version up to 13.2.
How can I fix CVE-2022-35260?
To fix CVE-2022-35260, update to curl version 7.86.0 or later.
Where can I find more information about CVE-2022-35260?
You can find more information about CVE-2022-35260 in the following references: [Link 1](https://support.apple.com/en-us/HT213604), [Link 2](https://support.apple.com/en-us/HT213605).