Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2022-32207

Description

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

POC

Reference

- http://seclists.org/fulldisclosure/2022/Oct/41

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/JtMotoX/docker-trivy

- https://github.com/letranduytan/SecureFirewall-OSHardeningforWebOS

- https://github.com/maxim12z/ECommerce

- https://github.com/neo9/fluentd

- https://github.com/okostine-panw/pc_scripts