CVE-2021-22925
published 2021-08-05CVE-2021-22925: curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
4.93%
91.2th percentile
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | macos | — | — |
| apple | macos | — | — |
| apple | macos | — | — |
| apple | macos | — | — |
| apple | macos | — | — |
| apple | macos | — | — |
| apple | macos | — | — |
| apple | macos | — | — |
| apple | macos | — | — |
| apple | macos | — | — |
| apple | macos_big_sur | — | — |
| apple | security_update_2021-005_catalina | — | — |
| debian | curl | — | — |
| fedoraproject | fedora | — | — |
| haxx | curl | >= 0 < 7.67.0-r5 | 7.67.0-r5 |
| haxx | curl | >= 0 < 7.78.0-r0 | 7.78.0-r0 |
| haxx | curl | >= 0 < 7.78.0-r0 | 7.78.0-r0 |
| haxx | curl | >= 0 < 7.78.0-r0 | 7.78.0-r0 |
| haxx | curl | >= 0 < 7.78.0-r0 | 7.78.0-r0 |
| haxx | curl | >= 0 < 7.78.0-r0 | 7.78.0-r0 |
| haxx | curl | >= 0 < 7.78.0-r0 | 7.78.0-r0 |
| haxx | curl | >= 0 < 7.78.0-r0 | 7.78.0-r0 |
| haxx | curl | >= 0 < 7.78.0-r0 | 7.78.0-r0 |
| haxx | curl | >= 0 < 7.78.0-r0 | 7.78.0-r0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_msrc5.3MEDIUM
vendor_redhat3.1LOW
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
curl vulnerabilities
vendor_ubuntu·2023-02-27·CVSS 3.1
CVE-2021-22925 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled
TELNET connections when the -t option was used on the command line.
Uninitialized data possibly containing sensitive information could be sent
to the remote server, contrary to expectations. This issue was only fixed
in Ubuntu 14.04 ESM. (CVE-2021-22898, CVE-2021-22925)
It was discovered that curl incorrectly handled denials when using HTTP
proxies. A remote attacker could use this issue to cause curl to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2022-43552)
Instructions: In general, a standard system update will make all the necessary changes.
CISA ICS
Siemens SINEMA Remote Connect Server
cisa_ics·2022-06-16·CVSS 3.7
[LOW] Siemens SINEMA Remote Connect Server
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEMA Remote Connect Server
Last RevisedJune 16, 2022
Alert CodeICSA-22-167-17
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEMA Remote Connect Server
- Vulnerabilities: Multiple
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges, disclose information, or allow code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Siemens products are affected:
- Siemens SINEMA Remote Connect Server: All v
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Ubuntu
curl vulnerability
vendor_ubuntu·2022-01-20·CVSS 3.1
CVE-2021-22898 [LOW] curl vulnerability
Title: curl vulnerability
Summary: curl could be made to expose sensitive information if it received a
specially crafted input.
USN-5021-1 fixed vulnerabilities in curl. This update provides
the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled
TELNET connections when the -t option was used on the command line.
Uninitialized data possibly containing sensitive information could be sent
to the remote server, contrary to expectations. (CVE-2021-22898,
CVE-2021-22925)
Instructions: In general, a standard system update will make all the necessary changes.
Apple
CVE-2021-22925: Security Update 2021-005 Catalina
vendor_apple·2021-09-13·CVSS 5.3
CVE-2021-22925 [MEDIUM] CVE-2021-22925: Security Update 2021-005 Catalina
Apple Security Update: About the security content of Security Update 2021-005 Catalina
Product: Security Update 2021-005 Catalina
CVE: CVE-2021-22925
Component: CUPS
Impact: A local user may be able to execute arbitrary files
Description: A URI parsing issue was addressed with improved parsing.
Apple
CVE-2021-22925: macOS Big Sur 11.6
vendor_apple·2021-09-13·CVSS 5.3
CVE-2021-22925 [MEDIUM] CVE-2021-22925: macOS Big Sur 11.6
Apple Security Update: About the security content of macOS Big Sur 11.6
Product: macOS Big Sur
Version: 11.6
CVE: CVE-2021-22925
Component: CUPS
Impact: A local user may be able to execute arbitrary files
Description: A URI parsing issue was addressed with improved parsing.
Microsoft
curl supports the `-t` command line option known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser
vendor_msrc·2021-08-10·CVSS 5.3
CVE-2021-22925 [MEDIUM] CWE-908 curl supports the `-t` command line option known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser
curl supports the `-t` command line option known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the comm
Ubuntu
curl vulnerabilities
vendor_ubuntu·2021-07-22·CVSS 3.1
CVE-2021-22898 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled
TELNET connections when the -t option was used on the command line.
Uninitialized data possibly containing sensitive information could be sent
to the remote server, contrary to expectations. (CVE-2021-22898,
CVE-2021-22925)
Harry Sintonen discovered that curl incorrectly reused connections in the
connection pool. This could result in curl reusing the wrong connections.
(CVE-2021-22924)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure
vendor_redhat·2021-07-21·CVSS 3.1
CVE-2021-22925 [LOW] CWE-908 curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure
curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.
A flaw was found in the way curl handled telnet protocol option for sending environment variables, which could lead to sending of uninitialized data from a stack-base
Debian
CVE-2021-22925: curl - curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in l...
vendor_debian·2021·CVSS 5.3
CVE-2021-22925 [MEDIUM] CVE-2021-22925: curl - curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in l...
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
curl vulnerabilities
osv·2023-02-27·CVSS 3.1
CVE-2021-22898 [LOW] curl vulnerabilities
curl vulnerabilities
Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled
TELNET connections when the -t option was used on the command line.
Uninitialized data possibly containing sensitive information could be sent
to the remote server, contrary to expectations. This issue was only fixed
in Ubuntu 14.04 ESM. (CVE-2021-22898, CVE-2021-22925)
It was discovered that curl incorrectly handled denials when using HTTP
proxies. A remote attacker could use this issue to cause curl to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2022-43552)
GHSA
GHSA-rjqf-6h27-xqfp: curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl
ghsa_unreviewed·2022-05-24
CVE-2021-22925 [MEDIUM] CWE-200 GHSA-rjqf-6h27-xqfp: curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.
OSV
curl vulnerability
osv·2022-01-20·CVSS 3.1
CVE-2021-22898 [LOW] curl vulnerability
curl vulnerability
USN-5021-1 fixed vulnerabilities in curl. This update provides
the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled
TELNET connections when the -t option was used on the command line.
Uninitialized data possibly containing sensitive information could be sent
to the remote server, contrary to expectations. (CVE-2021-22898,
CVE-2021-22925)
OSV
CVE-2021-22925: curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl
osv·2021-08-05·CVSS 5.3
CVE-2021-22925 [MEDIUM] CVE-2021-22925: curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.
OSV
curl vulnerabilities
osv·2021-07-22·CVSS 3.1
CVE-2021-22898 [LOW] curl vulnerabilities
curl vulnerabilities
Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled
TELNET connections when the -t option was used on the command line.
Uninitialized data possibly containing sensitive information could be sent
to the remote server, contrary to expectations. (CVE-2021-22898,
CVE-2021-22925)
Harry Sintonen discovered that curl incorrectly reused connections in the
connection pool. This could result in curl reusing the wrong connections.
(CVE-2021-22924)
No detection rules found.
No public exploits indexed.
http://seclists.org/fulldisclosure/2021/Sep/39http://seclists.org/fulldisclosure/2021/Sep/40https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://hackerone.com/reports/1223882https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/https://security.gentoo.org/glsa/202212-01https://security.netapp.com/advisory/ntap-20210902-0003/https://support.apple.com/kb/HT212804https://support.apple.com/kb/HT212805https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://seclists.org/fulldisclosure/2021/Sep/39http://seclists.org/fulldisclosure/2021/Sep/40https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://hackerone.com/reports/1223882https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/https://security.gentoo.org/glsa/202212-01https://security.netapp.com/advisory/ntap-20210902-0003/https://support.apple.com/kb/HT212804https://support.apple.com/kb/HT212805https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-08-05
Published