SUSE update for curl



| Updated: 2023-10-28
Risk Medium
Patch available YES
Number of vulnerabilities 6
CVE-ID CVE-2020-8231
CVE-2020-8284
CVE-2020-8285
CVE-2020-8286
CVE-2021-22876
CVE-2021-22898
CWE-ID CWE-825
CWE-200
CWE-674
CWE-299
CWE-457
Exploitation vector Network
Public exploit N/A
Vulnerable software
SUSE OpenStack Cloud Crowbar
Operating systems & Components / Operating system

SUSE Linux Enterprise Server for SAP
Operating systems & Components / Operating system

SUSE Linux Enterprise Server
Operating systems & Components / Operating system

SUSE OpenStack Cloud
Operating systems & Components / Operating system

libcurl4-debuginfo
Operating systems & Components / Operating system package or component

libcurl4-debuginfo-32bit
Operating systems & Components / Operating system package or component

libcurl4
Operating systems & Components / Operating system package or component

libcurl4-32bit
Operating systems & Components / Operating system package or component

curl-debugsource
Operating systems & Components / Operating system package or component

curl-debuginfo
Operating systems & Components / Operating system package or component

curl
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains information about 6 vulnerabilities.

1) Expired pointer dereference

EUVDB-ID: #VU45794

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2020-8231

CWE-ID: CWE-825 - Expired pointer dereference

Exploit availability: No

Description

The vulnerability allows an attacker to gain access to sensitive information.

The vulnerability exists due to expired pointer dereference error for CURLOPT_CONNECT_ONLY connections that may lead to information disclosure. If the application is using the CURLOPT_CONNECT_ONLY option to check if the website is accessible, an attacker might abuse this feature and force the application to re-use expired connection and send data intended to another connection to attacker controlled server.

Mitigation

Update the affected package curl to the latest version.

Vulnerable software versions

SUSE OpenStack Cloud Crowbar: 9

SUSE Linux Enterprise Server for SAP: 12-SP4

SUSE Linux Enterprise Server: 12-SP4-LTSS

SUSE OpenStack Cloud: 9

libcurl4-debuginfo: before 7.60.0-4.20.1

libcurl4-debuginfo-32bit: before 7.60.0-4.20.1

libcurl4: before 7.60.0-4.20.1

libcurl4-32bit: before 7.60.0-4.20.1

curl-debugsource: before 7.60.0-4.20.1

curl-debuginfo: before 7.60.0-4.20.1

curl: before 7.60.0-4.20.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2021/suse-su-20211786-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Information disclosure

EUVDB-ID: #VU48893

Risk: Medium

CVSSv4.0: 1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-8284

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the way cURL handles PASV responses. A remote attacker with control over malicious FTP server can use the PASV response to trick curl into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.

Mitigation

Update the affected package curl to the latest version.

Vulnerable software versions

SUSE OpenStack Cloud Crowbar: 9

SUSE Linux Enterprise Server for SAP: 12-SP4

SUSE Linux Enterprise Server: 12-SP4-LTSS

SUSE OpenStack Cloud: 9

libcurl4-debuginfo: before 7.60.0-4.20.1

libcurl4-debuginfo-32bit: before 7.60.0-4.20.1

libcurl4: before 7.60.0-4.20.1

libcurl4-32bit: before 7.60.0-4.20.1

curl-debugsource: before 7.60.0-4.20.1

curl-debuginfo: before 7.60.0-4.20.1

curl: before 7.60.0-4.20.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2021/suse-su-20211786-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Uncontrolled Recursion

EUVDB-ID: #VU48894

Risk: Low

CVSSv4.0: 1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2020-8285

CWE-ID: CWE-674 - Uncontrolled Recursion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due tu uncontrolled recursion when processing FTP responses within the wildcard matching functionality, which allows a callback (set with <a href="https://curl.se/libcurl/c/CURLOPT_CHUNK_BGN_FUNCTION.html">CURLOPT_CHUNK_BGN_FUNCTION</a>) to return information back to libcurl on how to handle a specific entry in a directory when libcurl iterates over a list of all available entries. A remote attacker who controls the malicious FTP server can trick the victim to connect to it and crash the application, which is using the affected libcurl version.

Mitigation

Update the affected package curl to the latest version.

Vulnerable software versions

SUSE OpenStack Cloud Crowbar: 9

SUSE Linux Enterprise Server for SAP: 12-SP4

SUSE Linux Enterprise Server: 12-SP4-LTSS

SUSE OpenStack Cloud: 9

libcurl4-debuginfo: before 7.60.0-4.20.1

libcurl4-debuginfo-32bit: before 7.60.0-4.20.1

libcurl4: before 7.60.0-4.20.1

libcurl4-32bit: before 7.60.0-4.20.1

curl-debugsource: before 7.60.0-4.20.1

curl-debuginfo: before 7.60.0-4.20.1

curl: before 7.60.0-4.20.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2021/suse-su-20211786-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Improper Check for Certificate Revocation

EUVDB-ID: #VU48895

Risk: Medium

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-8286

CWE-ID: CWE-299 - Improper Check for Certificate Revocation

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrectly implemented checks for OCSP stapling. A remote attacker can provide a fraudulent OCSP response that would appear fine, instead of the real one.

Mitigation

Update the affected package curl to the latest version.

Vulnerable software versions

SUSE OpenStack Cloud Crowbar: 9

SUSE Linux Enterprise Server for SAP: 12-SP4

SUSE Linux Enterprise Server: 12-SP4-LTSS

SUSE OpenStack Cloud: 9

libcurl4-debuginfo: before 7.60.0-4.20.1

libcurl4-debuginfo-32bit: before 7.60.0-4.20.1

libcurl4: before 7.60.0-4.20.1

libcurl4-32bit: before 7.60.0-4.20.1

curl-debugsource: before 7.60.0-4.20.1

curl-debuginfo: before 7.60.0-4.20.1

curl: before 7.60.0-4.20.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2021/suse-su-20211786-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Information disclosure

EUVDB-ID: #VU51821

Risk: Medium

CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2021-22876

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.

Mitigation

Update the affected package curl to the latest version.

Vulnerable software versions

SUSE OpenStack Cloud Crowbar: 9

SUSE Linux Enterprise Server for SAP: 12-SP4

SUSE Linux Enterprise Server: 12-SP4-LTSS

SUSE OpenStack Cloud: 9

libcurl4-debuginfo: before 7.60.0-4.20.1

libcurl4-debuginfo-32bit: before 7.60.0-4.20.1

libcurl4: before 7.60.0-4.20.1

libcurl4-32bit: before 7.60.0-4.20.1

curl-debugsource: before 7.60.0-4.20.1

curl-debuginfo: before 7.60.0-4.20.1

curl: before 7.60.0-4.20.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2021/suse-su-20211786-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Use of uninitialized variable

EUVDB-ID: #VU53587

Risk: Medium

CVSSv4.0: 1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2021-22898

CWE-ID: CWE-457 - Use of Uninitialized Variable

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to usage of uninitialized variable in code, responsible for processing TELNET requests when parsing NEW_ENV variables. A remote attacker can force the affected application to connect to a telnet server under attackers control and read up to 1800 bytes from the uninitialized memory on the libcurl client system.

Proof of concept:

curl telnet://example.com -tNEW_ENV=a,bbbbbb (256 'b's)

Mitigation

Update the affected package curl to the latest version.

Vulnerable software versions

SUSE OpenStack Cloud Crowbar: 9

SUSE Linux Enterprise Server for SAP: 12-SP4

SUSE Linux Enterprise Server: 12-SP4-LTSS

SUSE OpenStack Cloud: 9

libcurl4-debuginfo: before 7.60.0-4.20.1

libcurl4-debuginfo-32bit: before 7.60.0-4.20.1

libcurl4: before 7.60.0-4.20.1

libcurl4-32bit: before 7.60.0-4.20.1

curl-debugsource: before 7.60.0-4.20.1

curl-debuginfo: before 7.60.0-4.20.1

curl: before 7.60.0-4.20.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2021/suse-su-20211786-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###