CVE-2021-22898 Information
Description
curl 7.7 through 7.76.1 suffers from an information disclosure when the -t command line option known as CURLOPT_TELNETOPTIONS in libcurl is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables libcurl could be made to pass on uninitialized data from a stack based buffer to the server resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Reference
https://hackerone.com/reports/1176461
https://github.com/curl/curl/commit/39ce47f219b09c380b81f89fe54ac586c8db6bde
https://github.com/curl/curl/commit/39ce47f219b09c380b81f89fe54ac586c8db6bde
https://curl.se/docs/CVE-2021-22898.html
https://curl.se/docs/CVE-2021-22898.html
https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c@%3Cissues.guacamole.apache.org%3E
https://www.oracle.com//security-alerts/cpujul2021.html
http://www.openwall.com/lists/oss-security/2021/07/21/4
[oss-security]
20210721
[SECURITY
ADVISORY]
curl:
TELNET
stack
contents
disclosure
again
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/POOC3UV7V6L4CJ5KA2PTWTNUV5Y72T3Q/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
https://lists.debian.org/debian-lts-announce/2021/08/msg00017.html
[debian-lts-announce]
20210813
[SECURITY]
[DLA
2734-1]
curl
security
update
https://www.oracle.com/security-alerts/cpujan2022.html
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
https://www.oracle.com/security-alerts/cpuapr2022.html
curl
7.7
through
7.76.1
suffers
from
an
information
disclosure
when
the
-t
command
line
option
known
as
CURLOPT_TELNETOPTIONS
in
libcurl
is
used
to
send
variable=content
pairs
to
TELNET
servers.
Due
to
a
flaw
in
the
option
parser
for
sending
NEW_ENV
variables
libcurl
could
be
made
to
pass
on
uninitialized
data
from
a
stack
based
buffer
to
the
server
resulting
in
potentially
revealing
sensitive
internal
information
to
the
server
using
a
clear-text
network
protocol.
cpe:2.3:a:haxx:curl::::::::
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
3.1
Share on: