CVE-2022-43552

MEDIUM

curl < 7.87.0 - Use-After-Free in HTTP Proxy Tunnel Shutdown

Title source: llm
STIX 2.1

Description

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

References (5)

Core 5
Core References
Exploit, Issue Tracking, Third Party Advisory
https://hackerone.com/reports/1764858
Mailing List, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2023/Mar/17
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202310-12

Scores

CVSS v3 5.9
EPSS 0.0010
EPSS Percentile 27.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (4)
apple/macos 13.0 - 13.3
haxx/curl < 7.87.0
splunk/universal_forwarder 9.1.0
splunk/universal_forwarder 8.2.0 - 8.2.12
Published Feb 09, 2023
Tracked Since Feb 18, 2026