CVE-2021-22946
published 2021-09-29CVE-2021-22946: A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command…
high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 12.3 | 12.3 |
| apple | macos_monterey | — | — |
| debian | curl | < curl 7.79.1-1 (bookworm) | curl 7.79.1-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| haxx | curl | >= 0 < 7.74.0-1.3+deb11u2 | 7.74.0-1.3+deb11u2 |
| haxx | curl | >= 0 < 7.79.1-1 | 7.79.1-1 |
| haxx | curl | >= 0 < 7.79.1-1 | 7.79.1-1 |
| haxx | curl | >= 0 < 7.79.1-1 | 7.79.1-1 |
| haxx | curl | >= 0 < 7.58.0-2ubuntu3.16 | 7.58.0-2ubuntu3.16 |
| haxx | curl | >= 0 < 7.58.0-2ubuntu3.15 | 7.58.0-2ubuntu3.15 |
| haxx | curl | >= 0 < 7.68.0-1ubuntu2.7 | 7.68.0-1ubuntu2.7 |
| haxx | curl | >= 0 < 7.35.0-1ubuntu2.20+esm8 | 7.35.0-1ubuntu2.20+esm8 |
| haxx | curl | >= 0 < 7.35.0-1ubuntu2.20+esm9 | 7.35.0-1ubuntu2.20+esm9 |
| haxx | curl | >= 0 < 7.47.0-1ubuntu2.19+esm1 | 7.47.0-1ubuntu2.19+esm1 |
| haxx | curl | >= 0 < 7.47.0-1ubuntu2.19+esm2 | 7.47.0-1ubuntu2.19+esm2 |
| haxx | curl | >= 7.20.0 < 7.79.0 | 7.79.0 |
| https | github.com_curl_curl | — | — |
| msrc | cbl2_curl_7.82.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_curl_7.76.0-6_on_cbl_mariner_1.0 | — | — |
| oracle | commerce_guided_search | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv9.1CRITICAL