CVE-2021-22947
published 2021-09-29CVE-2021-22947: When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and…
PriorityP335medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
2.80%
84.9th percentile
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 12.3 | 12.3 |
| apple | macos_monterey | — | — |
| debian | curl | < curl 7.79.1-1 (bookworm) | curl 7.79.1-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| haxx | curl | >= 0 < 7.74.0-1.3+deb11u2 | 7.74.0-1.3+deb11u2 |
| haxx | curl | >= 0 < 7.79.1-1 | 7.79.1-1 |
| haxx | curl | >= 0 < 7.79.1-1 | 7.79.1-1 |
| haxx | curl | >= 0 < 7.79.1-1 | 7.79.1-1 |
| haxx | curl | >= 0 < 7.58.0-2ubuntu3.16 | 7.58.0-2ubuntu3.16 |
| haxx | curl | >= 0 < 7.58.0-2ubuntu3.15 | 7.58.0-2ubuntu3.15 |
| haxx | curl | >= 0 < 7.68.0-1ubuntu2.7 | 7.68.0-1ubuntu2.7 |
| haxx | curl | >= 0 < 7.35.0-1ubuntu2.20+esm8 | 7.35.0-1ubuntu2.20+esm8 |
| haxx | curl | >= 0 < 7.35.0-1ubuntu2.20+esm9 | 7.35.0-1ubuntu2.20+esm9 |
| haxx | curl | >= 0 < 7.47.0-1ubuntu2.19+esm1 | 7.47.0-1ubuntu2.19+esm1 |
| haxx | curl | >= 0 < 7.47.0-1ubuntu2.19+esm2 | 7.47.0-1ubuntu2.19+esm2 |
| haxx | curl | >= 7.20.0 < 7.79.0 | 7.79.0 |
| https | github.com_curl_curl | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv9.1CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_debian5.9MEDIUM
vendor_msrc5.9CRITICAL
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2021-22947: macOS Monterey 12.3
vendor_apple·2022-03-14·CVSS 5.9
CVE-2021-22947 [MEDIUM] CVE-2021-22947: macOS Monterey 12.3
Apple Security Update: About the security content of macOS Monterey 12.3
Product: macOS Monterey
Version: 12.3
CVE: CVE-2021-22947
Component: CVE-2021-22947
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Microsoft
Open Source Curl Remote Code Execution Vulnerability
vendor_msrc·2022-01-11·CVSS 5.9
CVE-2021-22947 [MEDIUM] Open Source Curl Remote Code Execution Vulnerability
Open Source Curl Remote Code Execution Vulnerability
FAQ: Why is this a Hacker One CVE?
This CVE is regarding a vulnerability in the curl open source library which is used by Windows. The January 2022 Windows Security Updates includes the most recent version of this library which addresses the vulnerability and others. Please see curl security problems for information on all of the vulnerabilities that have been addressed.
Open Source Software: Open Source Software
HackerOne: HackerOne
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5009557
Reference: h
Ubuntu
curl vulnerabilities
vendor_ubuntu·2021-09-21·CVSS 9.1
[CRITICAL] curl vulnerabilities
Title: curl vulnerabilities
Summary: USN-5079-1 introduced a regression in curl.
USN-5079-1 fixed vulnerabilities in curl. One of the fixes introduced a
regression on Ubuntu 18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that curl incorrect handled memory when sending data to
an MQTT server. A remote attacker could use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2021-22945)
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered
Ubuntu
curl regression
vendor_ubuntu·2021-09-21·CVSS 7.5
CVE-2021-22946 [HIGH] curl regression
Title: curl regression
Summary: USN-5079-2 introduced a regression in curl.
USN-5079-2 fixed vulnerabilities in curl. One of the fixes introduced a
regression. This update fixes the problem.
Original advisory details:
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered that curl incorrectly handled responses
received before STARTTLS. A remote attacker could possibly use this issue
to inject responses and intercept communications. (CVE-2021-22947)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2021-09-15·CVSS 7.5
CVE-2021-22946 [HIGH] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
USN-5079-1 fixed several vulnerabilities in curl. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered that curl incorrectly handled responses
received before STARTTLS. A remote attacker could possibly use this issue
to inject responses and intercept communications. (CVE-2021-22947)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2021-09-15·CVSS 9.1
CVE-2021-22947 [CRITICAL] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
It was discovered that curl incorrect handled memory when sending data to
an MQTT server. A remote attacker could use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2021-22945)
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered that curl incorrectly handled responses
received before STARTTLS. A remote attacker could possibly use this issue
to inject responses and intercept communications. (CVE-2021-22947)
Instructions: In ge
Red Hat
curl: Server responses received before STARTTLS processed after TLS handshake
vendor_redhat·2021-09-15·CVSS 5.9
CVE-2021-22947 [MEDIUM] CWE-319 curl: Server responses received before STARTTLS processed after TLS handshake
curl: Server responses received before STARTTLS processed after TLS handshake
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server.
A flaw was found in curl. The flaw l
Debian
CVE-2021-22947: curl - When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve...
vendor_debian·2021·CVSS 5.9
CVE-2021-22947 [MEDIUM] CVE-2021-22947: curl - When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve...
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server.
Scope: local
bookworm: resolved (fixed in 7.79.1-1)
bullseye: resolved (fixed in 7.74.0-1.3+deb11u2)
forky: resolved
GHSA
GHSA-94jh-wwgf-cmmc: When curl >= 7
ghsa_unreviewed·2022-05-24
CVE-2021-22947 [MEDIUM] CWE-345 GHSA-94jh-wwgf-cmmc: When curl >= 7
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server.
OSV
CVE-2021-22947: When curl >= 7
osv·2021-09-29·CVSS 5.9
CVE-2021-22947 [MEDIUM] CVE-2021-22947: When curl >= 7
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server.
OSV
curl vulnerabilities
osv·2021-09-21·CVSS 9.1
CVE-2021-22945 [CRITICAL] curl vulnerabilities
curl vulnerabilities
USN-5079-1 fixed vulnerabilities in curl. One of the fixes introduced a
regression on Ubuntu 18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that curl incorrect handled memory when sending data to
an MQTT server. A remote attacker could use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2021-22945)
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered that curl incorrectly handled responses
received before START
OSV
curl regression
osv·2021-09-21·CVSS 7.5
CVE-2021-22946 [HIGH] curl regression
curl regression
USN-5079-2 fixed vulnerabilities in curl. One of the fixes introduced a
regression. This update fixes the problem.
Original advisory details:
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered that curl incorrectly handled responses
received before STARTTLS. A remote attacker could possibly use this issue
to inject responses and intercept communications. (CVE-2021-22947)
OSV
curl vulnerabilities
osv·2021-09-15·CVSS 9.1
CVE-2021-22945 [CRITICAL] curl vulnerabilities
curl vulnerabilities
It was discovered that curl incorrect handled memory when sending data to
an MQTT server. A remote attacker could use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2021-22945)
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered that curl incorrectly handled responses
received before STARTTLS. A remote attacker could possibly use this issue
to inject responses and intercept communications. (CVE-2021-22947)
OSV
curl vulnerabilities
osv·2021-09-15·CVSS 7.5
CVE-2021-22946 [HIGH] curl vulnerabilities
curl vulnerabilities
USN-5079-1 fixed several vulnerabilities in curl. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)
Patrick Monnerat discovered that curl incorrectly handled responses
received before STARTTLS. A remote attacker could possibly use this issue
to inject responses and intercept communications. (CVE-2021-22947)
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2021-22947: STARTTLS protocol injection via MITM
hackerone·2021-09-24·CVSS 5.9
CVE-2021-22947 [MEDIUM] CVE-2021-22947: STARTTLS protocol injection via MITM
CVE-2021-22947: STARTTLS protocol injection via MITM
## Summary:
A man-in-the-middle can inject cleartext forged responses to future encrypted commands by pipelining them to the STARTTLS response.
## Steps To Reproduce:
Use the attached test case within the curl test system. It is based on IMAP FETCH with explicit TLS. Upon test failure, the downloaded file contains "You've been hacked!" rather than the requested mail.
## Impact
Mailbox content forgery (IMAP, POP3).
Sent mail content forgery (SMTP).
Krebs
‘Wormable’ Flaw Leads January 2022 Patch Tuesday
blogs_krebs·2022-01-11·CVSS 9.8
[CRITICAL] ‘Wormable’ Flaw Leads January 2022 Patch Tuesday
Microsoft today released updates to plug nearly 120 security holes in Windows and supported software. Six of the vulnerabilities were publicly detailed already, potentially giving attackers a head start in figuring out how to exploit them in unpatched systems. More concerning, Microsoft warns that one of the flaws fixed this month is “wormable,” meaning no human interaction would be required for an attack to spread from one vulnerable Windows box to another.
Nine of the vulnerabilities fixed in this month’s Patch Tuesday received Microsoft’s “critical” rating, meaning malware or miscreants can exploit them to gain remote access to vulnerable Windows systems through no help from the user.
By all accounts, the most severe flaw addressed today is CVE-2022-21907, a critical, remote code exec
Krebs
‘Wormable’ Flaw Leads January 2022 Patch Tuesday
blogs_krebs·2022-01-11·CVSS 9.8
[CRITICAL] ‘Wormable’ Flaw Leads January 2022 Patch Tuesday
Microsoft today released updates to plug nearly 120 security holes in Windows and supported software. Six of the vulnerabilities were publicly detailed already, potentially giving attackers a head start in figuring out how to exploit them in unpatched systems. More concerning, Microsoft warns that one of the flaws fixed this month is “wormable,” meaning no human interaction would be required for an attack to spread from one vulnerable Windows box to another.
Nine of the vulnerabilities fixed in this month’s Patch Tuesday received Microsoft’s “critical” rating, meaning malware or miscreants can exploit them to gain remote access to vulnerable Windows systems through no help from the user.
By all accounts, the most severe flaw addressed today is CVE-2022-21907, a critical, remote code exec
http://seclists.org/fulldisclosure/2022/Mar/29https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://hackerone.com/reports/1334763https://lists.debian.org/debian-lts-announce/2021/09/msg00022.htmlhttps://lists.debian.org/debian-lts-announce/2022/08/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/https://security.gentoo.org/glsa/202212-01https://security.netapp.com/advisory/ntap-20211029-0003/https://support.apple.com/kb/HT213183https://www.debian.org/security/2022/dsa-5197https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://seclists.org/fulldisclosure/2022/Mar/29https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://hackerone.com/reports/1334763https://lists.debian.org/debian-lts-announce/2021/09/msg00022.htmlhttps://lists.debian.org/debian-lts-announce/2022/08/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/https://security.gentoo.org/glsa/202212-01https://security.netapp.com/advisory/ntap-20211029-0003/https://support.apple.com/kb/HT213183https://www.debian.org/security/2022/dsa-5197https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-09-29
Published