CVE
CVE-2022-32206
CVE ID |
CVE-2022-32206
|
---|---|
CVSS Score |
6.5
|
Operating System | |
Affected Versions |
CentOS 8
|
Patched Versions |
7.61.1-22_ol001.el8
|
Patch Date |
|
Additional Information
NVD Listing: https://nvd.nist.gov/vuln/detail/CVE-2022-32206
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.