CVE-2021-22898
published 2021-06-11CVE-2021-22898: curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send…
PriorityP419low3.1CVSS 3.1
AVNACHPRNUIRSUCLINAN
EPSS
4.38%
90.2th percentile
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | curl | < curl 7.79.1-1 (bookworm) | curl 7.79.1-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| haxx | curl | >= 0 < 7.74.0-1.3+deb11u2 | 7.74.0-1.3+deb11u2 |
| haxx | curl | >= 0 < 7.79.1-1 | 7.79.1-1 |
| haxx | curl | >= 0 < 7.79.1-1 | 7.79.1-1 |
| haxx | curl | >= 0 < 7.79.1-1 | 7.79.1-1 |
| haxx | curl | >= 0 < 7.58.0-2ubuntu3.14 | 7.58.0-2ubuntu3.14 |
| haxx | curl | >= 0 < 7.68.0-1ubuntu2.6 | 7.68.0-1ubuntu2.6 |
| haxx | curl | >= 0 < 7.35.0-1ubuntu2.20+esm14 | 7.35.0-1ubuntu2.20+esm14 |
| haxx | curl | >= 0 < 7.47.0-1ubuntu2.19+esm3 | 7.47.0-1ubuntu2.19+esm3 |
| haxx | curl | >= 0 < 7.47.0-1ubuntu2.19+esm7 | 7.47.0-1ubuntu2.19+esm7 |
| haxx | curl | 7.7 – 7.76.1 | — |
| https | github.com_curl_curl | — | — |
| msrc | cbl2_curl_7.76.0-5_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_curl_7.76.0-2_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| oracle | communications_cloud_native_core_service_communication_proxy | — | — |
| oracle | essbase | < 11.1.2.4.047 | 11.1.2.4.047 |
| oracle | essbase | >= 21.0 < 21.3 | 21.3 |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv3.1LOW
vendor_debian3.1LOW
vendor_msrc3.1LOW
vendor_redhat3.1LOW
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
curl vulnerabilities
vendor_ubuntu·2023-02-27·CVSS 3.1
CVE-2021-22925 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled
TELNET connections when the -t option was used on the command line.
Uninitialized data possibly containing sensitive information could be sent
to the remote server, contrary to expectations. This issue was only fixed
in Ubuntu 14.04 ESM. (CVE-2021-22898, CVE-2021-22925)
It was discovered that curl incorrectly handled denials when using HTTP
proxies. A remote attacker could use this issue to cause curl to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2022-43552)
Instructions: In general, a standard system update will make all the necessary changes.
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Ubuntu
curl vulnerability
vendor_ubuntu·2022-01-20·CVSS 3.1
CVE-2021-22898 [LOW] curl vulnerability
Title: curl vulnerability
Summary: curl could be made to expose sensitive information if it received a
specially crafted input.
USN-5021-1 fixed vulnerabilities in curl. This update provides
the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled
TELNET connections when the -t option was used on the command line.
Uninitialized data possibly containing sensitive information could be sent
to the remote server, contrary to expectations. (CVE-2021-22898,
CVE-2021-22925)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2021-07-22·CVSS 3.1
CVE-2021-22898 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled
TELNET connections when the -t option was used on the command line.
Uninitialized data possibly containing sensitive information could be sent
to the remote server, contrary to expectations. (CVE-2021-22898,
CVE-2021-22925)
Harry Sintonen discovered that curl incorrectly reused connections in the
connection pool. This could result in curl reusing the wrong connections.
(CVE-2021-22924)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure
vendor_redhat·2021-07-21·CVSS 3.1
CVE-2021-22925 [LOW] CWE-908 curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure
curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.
A flaw was found in the way curl handled telnet protocol option for sending environment variables, which could lead to sending of uninitialized data from a stack-base
Microsoft
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option known as `CURLOPT_TELNETOPTIONS` in libcurl is used to send variable=content pairs to TELNET servers. D
vendor_msrc·2021-06-08·CVSS 3.1
CVE-2021-22898 [LOW] CWE-909 curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option known as `CURLOPT_TELNETOPTIONS` in libcurl is used to send variable=content pairs to TELNET servers. D
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option known as `CURLOPT_TELNETOPTIONS` in libcurl is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables libcurl could be made to pass on uninitialized data from a stack based buffer to the server resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the ope
Red Hat
curl: TELNET stack contents disclosure
vendor_redhat·2021-05-26·CVSS 3.1
CVE-2021-22898 [LOW] CWE-908 curl: TELNET stack contents disclosure
curl: TELNET stack contents disclosure
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.
A flaw was found in the way curl handled telnet protocol option for sending environment variables, which could lead to sending of uninitialized data from a stack-based buffer to the server. This issue leads to potentially revealing sensitive internal information to the server using
Debian
CVE-2021-22898: curl - curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` com...
vendor_debian·2021·CVSS 3.1
CVE-2021-22898 [LOW] CVE-2021-22898: curl - curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` com...
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.
Scope: local
bookworm: resolved (fixed in 7.79.1-1)
bullseye: resolved (fixed in 7.74.0-1.3+deb11u2)
forky: resolved (fixed in 7.79.1-1)
sid: resolved (fixed in 7.79.1-1)
trixie: resolved (fixed in 7.79.1-1)
OSV
curl vulnerabilities
osv·2023-02-27·CVSS 3.1
CVE-2021-22898 [LOW] curl vulnerabilities
curl vulnerabilities
Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled
TELNET connections when the -t option was used on the command line.
Uninitialized data possibly containing sensitive information could be sent
to the remote server, contrary to expectations. This issue was only fixed
in Ubuntu 14.04 ESM. (CVE-2021-22898, CVE-2021-22925)
It was discovered that curl incorrectly handled denials when using HTTP
proxies. A remote attacker could use this issue to cause curl to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2022-43552)
GHSA
GHSA-7w8r-q58w-5wcr: curl 7
ghsa_unreviewed·2022-05-24
CVE-2021-22898 [HIGH] CWE-200 GHSA-7w8r-q58w-5wcr: curl 7
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.
OSV
curl vulnerability
osv·2022-01-20·CVSS 3.1
CVE-2021-22898 [LOW] curl vulnerability
curl vulnerability
USN-5021-1 fixed vulnerabilities in curl. This update provides
the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled
TELNET connections when the -t option was used on the command line.
Uninitialized data possibly containing sensitive information could be sent
to the remote server, contrary to expectations. (CVE-2021-22898,
CVE-2021-22925)
OSV
curl vulnerabilities
osv·2021-07-22·CVSS 3.1
CVE-2021-22898 [LOW] curl vulnerabilities
curl vulnerabilities
Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled
TELNET connections when the -t option was used on the command line.
Uninitialized data possibly containing sensitive information could be sent
to the remote server, contrary to expectations. (CVE-2021-22898,
CVE-2021-22925)
Harry Sintonen discovered that curl incorrectly reused connections in the
connection pool. This could result in curl reusing the wrong connections.
(CVE-2021-22924)
OSV
CVE-2021-22898: curl 7
osv·2021-06-11·CVSS 3.1
CVE-2021-22898 [LOW] CVE-2021-22898: curl 7
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2021-22925: TELNET stack contents disclosure again
hackerone·2021-07-21·CVSS 3.1
CVE-2021-22925 [LOW] CVE-2021-22925: TELNET stack contents disclosure again
CVE-2021-22925: TELNET stack contents disclosure again
## Summary:
CVE-2021-22898: TELNET stack contents disclosure (#1176461) issue was recently reported for curl and it was addressed in curl 7.77.0:
https://curl.se/docs/CVE-2021-22898.html
https://github.com/curl/curl/commit/39ce47f219b09c380b81f89fe54ac586c8db6bde
https://hackerone.com/reports/1176461
However, the fix applied is not correct and does not completely address the issue. It helps in cases when long environment variable name is used (`'a'*256 + ',b'`), but not when the name is short and only the value is long (`'a,' + 'b'*256`, which is the example mentioned in the curl project advisory).
## Steps To Reproduce:
Follow the steps form #1176461, only use NEW_ENV option with short name and long value, such as:
```
$ curl t
HackerOne
CVE-2021-22898: TELNET stack contents disclosure
hackerone·2021-05-26·CVSS 3.1
CVE-2021-22898 [LOW] CVE-2021-22898: TELNET stack contents disclosure
CVE-2021-22898: TELNET stack contents disclosure
## Summary:
lib/telnet.c `suboption` function incorrecly checks for the `sscanf` return value. Instead of checking that 2 elements are parsed, the code also continues if just one element matches:
`if(sscanf(v->data, "%127[^,],%127s", varname, varval)) {`
As such it is possible to construct environment values that don't update the `varval` buffer and instead use the previous value. In combination of advancing in the `temp` buffer by `strlen(v->data) + 1`, this means that there will be uninitialized gaps in the generated output `temp` buffer. These gaps will contain whatever stack contents from previous operation of the application.
Fortunately the environment is controlled by the client and not the server. As such this vulnerability can't b
http://www.openwall.com/lists/oss-security/2021/07/21/4https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://curl.se/docs/CVE-2021-22898.htmlhttps://github.com/curl/curl/commit/39ce47f219b09c380b81f89fe54ac586c8db6bdehttps://hackerone.com/reports/1176461https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/08/msg00017.htmlhttps://lists.debian.org/debian-lts-announce/2022/08/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POOC3UV7V6L4CJ5KA2PTWTNUV5Y72T3Q/https://www.debian.org/security/2022/dsa-5197https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttp://www.openwall.com/lists/oss-security/2021/07/21/4https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://curl.se/docs/CVE-2021-22898.htmlhttps://github.com/curl/curl/commit/39ce47f219b09c380b81f89fe54ac586c8db6bdehttps://hackerone.com/reports/1176461https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/08/msg00017.htmlhttps://lists.debian.org/debian-lts-announce/2022/08/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/POOC3UV7V6L4CJ5KA2PTWTNUV5Y72T3Q/https://www.debian.org/security/2022/dsa-5197https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.html
2021-06-11
Published