Back to search
CVE-2022-32208
Published: Jul 7, 2022
Modified: May 5, 2025
PUBLISHED
Description
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
| Vendor | Product | Versions |
|---|---|---|
n/a | https://github.com/curl/curl | affected Fixed in 7.84.0 |
Weaknesses (CWE)
References
FEDORA-2022-1b3d7f6973
vendor-advisory
DSA-5197
vendor-advisory
20221030 APPLE-SA-2022-10-24-2 macOS Ventura 13
mailing-list
GLSA-202212-01
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now