An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Curl | Haxx | 7.65.0 (including) | 7.82.0 (including) |
Red Hat Enterprise Linux 9 | RedHat | curl-0:7.76.1-19.el9 | * |
Red Hat Enterprise Linux 9 | RedHat | curl-0:7.76.1-19.el9 | * |
Curl | Ubuntu | devel | * |
Curl | Ubuntu | focal | * |
Curl | Ubuntu | impish | * |
Curl | Ubuntu | jammy | * |
Curl | Ubuntu | upstream | * |