🪟 Windows TippsWindows 11: Nach Apples Erfolg ändert auch Microsoft den Kurs(26.08.2026 um 09:55 Uhr)
🪟 Windows TippsStichtag 13. Oktober: Windows 11 legt den Schalter um(02.09.2026 um 16:09 Uhr)
🪟 Windows TippsVersteckt in Windows 11: Nutzer entdeckt geheimes Feature(10.09.2026 um 08:37 Uhr)
🪟 Windows TippsWindows 11: Nach Apples Erfolg ändert auch Microsoft den Kurs(26.08.2026 um 09:55 Uhr)
🪟 Windows TippsStichtag 13. Oktober: Windows 11 legt den Schalter um(02.09.2026 um 16:09 Uhr)
🪟 Windows TippsVersteckt in Windows 11: Nutzer entdeckt geheimes Feature(10.09.2026 um 08:37 Uhr)

🕵️ Sicherheitslücken 🕛 vor 4 Jahren 2 Min Lesezeit CVE-2022-32207
0

curl: CVE-2022-32207: Unpreserved file permissions

Cyber Threat & Vulnerability Dossier CVSS 7.5 HIGH (Heuristik) EPSS 32.3%
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
Im CVE-Radar öffnen
↗ Quelle (vulners.com)
🗣️ Stimme:

image
Summary: Curl fails to preserve file permissions when writing: - CURLOPT_COOKIEJAR database - CURLOPT_ALTSVC database - CURLOPT_HSTS database Instead the permissions is always reset to 0666 & ~umask if the file is updated. As a result a file that was before protected against read access by other users becomes other user readable (as long as umask doesn't have bit 2 set). Out of these files only the CURLOPT_COOKIEJAR is likely to contain sensitive information. In addition curl will replace softlink to the database with locally written database, or if the application is run privileged, specifying "/dev/null" as a file name can lead to system overwriting the special file and result in inoperable system. This is CWE-281: Improper Preservation of Permissions Steps To Reproduce: umask 022 install -m 600 /dev/null cookie.db curl -b cookie.db -c cookie.db https://google.com ls -l cookie.db At least for CURLOPT_COOKIEJAR this vulnerability was introduced in https://github.com/curl/curl/commit/b834890a3fa3f525cd8ef4e99554cdb4558d7e1b - this change was introduced to fix a issue https://github.com/curl/curl/issues/4914 Fix recommendations If a file file is created and moved over a the old one, only do this if the file is regular file. Anything else is likely going to end up causing unexpected behaviour, outright failing, or if the user has high enough permissions, damage to the operating system. Safe cloning of file permissions can only be achieved if the owner / group of the file...
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf vulners.com.
↗ Original-Artikel auf vulners.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
The Gemini desktop app is now available for Windows
1 Quelle
ChatGPT automatically logged out [Fix]
1 Quelle
Windows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten curl: CVE-2022-32207: Unpreserved file permissions

Thematisch verwandte Begriffe: curl, CVE202232207, Unpreserved, file · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...