CVE-2022-27781

Published Jun 2, 2022

Last updated 7 days ago

Overview

Description
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.
Source
support@hackerone.com
NVD status
Modified
Products
curl, debian_linux, hci_bootstrap_os, clustered_data_ontap, solidfire\,_enterprise_sds_\&_hci_storage_node, solidfire_\&_hci_management_node, hci_compute_node, h300s_firmware, h500s_firmware, h700s_firmware, h410s_firmware, universal_forwarder

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

CVSS 2.0

Type
Primary
Base score
5
Impact score
2.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

support@hackerone.com
CWE-400
nvd@nist.gov
CWE-835
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-835

Social media

Hype score
Not currently trending

Configurations