{"id":"CLSA-2022-1656959369","summary":"Fix CVE(s): CVE-2022-27782","details":"\n   * SECURITY UPDATE: libcurl would reuse a previously created connection even\n     when a TLS or SSH related option had been changed that should have\n     prohibited reuse.\n     - debian/patches/CVE-2022-27782-tls.patch: add missing primary checks of\n       tls parameters before connection reuse\n     - CVE-2022-27782","modified":"2026-06-04T09:45:41.948031721Z","published":"2022-07-04T18:29:29Z","upstream":["CVE-2022-27782"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16_04/CLSA-2022-1656959369"}],"affected":[{"package":{"name":"curl","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/curl?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.47.0-1ubuntu2.23+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656959369.json"}},{"package":{"name":"libcurl3","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libcurl3?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.47.0-1ubuntu2.23+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656959369.json"}},{"package":{"name":"libcurl3-gnutls","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libcurl3-gnutls?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.47.0-1ubuntu2.23+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656959369.json"}},{"package":{"name":"libcurl3-nss","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libcurl3-nss?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.47.0-1ubuntu2.23+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656959369.json"}},{"package":{"name":"libcurl4-doc","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libcurl4-doc?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.47.0-1ubuntu2.23+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656959369.json"}},{"package":{"name":"libcurl4-gnutls-dev","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libcurl4-gnutls-dev?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.47.0-1ubuntu2.23+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656959369.json"}},{"package":{"name":"libcurl4-nss-dev","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libcurl4-nss-dev?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.47.0-1ubuntu2.23+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656959369.json"}},{"package":{"name":"libcurl4-openssl-dev","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libcurl4-openssl-dev?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.47.0-1ubuntu2.23+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656959369.json"}}],"schema_version":"1.7.5"}