Information disclosure in cURL - CVE-2024-11053
Published: December 11, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an error when using a .netrc file for credentials and an instruction to follow HTTP redirects. The cURL library can leak credentials intended for the first URL prior to redirection. This however will only occur if the .netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.
Affected software
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
Basesystem Module
openSUSE Leap
openEuler
SmartFabric Manager
EasyApache
Infrastructure Technology
Oracle HTTP Server
APEX Cloud Platform for Red Hat OpenShift
PowerProtect Data Manager
IBM Cloud Pak for Business Automation
Nessus Network Monitor
MySQL Enterprise Backup
Communications Unified Assurance
SecurityCenter
LANTIME Operating System Firmware (LTOS)
Dell EMC VxRail Appliance
MySQL Server
mecab
mecab-ipadic
mecab-ipadic-EUCJP
curl (Ubuntu package)
libcurl4-debuginfo
curl
curl-debugsource
curl-debuginfo
libcurl4
libcurl3-gnutls (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl
libcurl-devel
curl-help
libcurl4-32bit
libcurl4-debuginfo-32bit
libcurl4-32bit-debuginfo
libcurl-devel-64bit
libcurl4-64bit
libcurl4-64bit-debuginfo
libcurl-devel-32bit
mysql-test
mysql-server
mysql-libs
mysql-errmsg
mysql-devel
mysql-common
mysql
mysql (Red Hat package)
curl-doc
libcurl-minimal
curl-minimal
libcurl3t64-gnutls (Ubuntu package)
libcurl4t64 (Ubuntu package)
Dell EMC Storage Monitoring and Reporting (SMR)
Storage Resource Manager
SmartFabric OS10
IBM CICS TX Advanced
How to mitigate CVE-2024-11053
SmartFabric Manager - update to 1.2.0
EasyApache - update to 4 2024-12-18
Nessus Network Monitor - update to 6.5.1
SecurityCenter - update to SC-202504.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.020
Dell EMC VxRail Appliance - update to 8.321
MySQL Server - addressed in versions 8.0.41, 8.4.4, 9.2.0
MySQL Enterprise Backup - addressed in versions 8.0.41, 8.4.4, 9.2.0
mecab - update to 0.996-2
mecab-ipadic - update to 2.7.0.20070801-17.0.1
mecab-ipadic-EUCJP - update to 2.7.0.20070801-17.0.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm21, 7.47.0-1ubuntu2.19+esm17, 7.58.0-2ubuntu3.24+esm10, 7.68.0-1ubuntu2.25, 7.68.0-1ubuntu2.25+esm5, 7.81.0-1ubuntu1.20, 8.5.0-2ubuntu10.6, 8.5.0-2ubuntu10.11, 8.9.1-2ubuntu2.2, 8.14.1-2ubuntu1.5, 8.18.0-1ubuntu2.3
libcurl4-debuginfo - addressed in versions 7.66.0-150200.4.81.1, 8.0.1-11.101.1, 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
curl - addressed in versions 7.66.0-150200.4.81.1, 8.0.1-11.101.1, 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
curl-debugsource - addressed in versions 7.66.0-150200.4.81.1, 8.0.1-11.101.1, 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
curl-debuginfo - addressed in versions 7.66.0-150200.4.81.1, 8.0.1-11.101.1, 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl4 - addressed in versions 7.66.0-150200.4.81.1, 8.0.1-11.101.1, 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.25, 7.81.0-1ubuntu1.20
libcurl3-nss (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.25, 7.81.0-1ubuntu1.20
libcurl4 (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.25, 7.81.0-1ubuntu1.20
curl-debugsource - addressed in versions 7.79.1-36, 8.4.0-14
libcurl - addressed in versions 7.79.1-36, 8.4.0-14
curl-debuginfo - addressed in versions 7.79.1-36, 8.4.0-14
libcurl-devel - addressed in versions 7.79.1-36, 8.4.0-14
curl - addressed in versions 7.79.1-36, 8.4.0-14
curl-help - addressed in versions 7.79.1-36, 8.4.0-14
libcurl4-32bit - addressed in versions 8.0.1-11.101.1, 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl4-debuginfo-32bit - update to 8.0.1-11.101.1
libcurl-devel - addressed in versions 8.0.1-11.101.1, 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl4-32bit-debuginfo - addressed in versions 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl-devel-64bit - addressed in versions 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl4-64bit - addressed in versions 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl4-64bit-debuginfo - addressed in versions 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl-devel-32bit - addressed in versions 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
mysql-test - update to 8.0.41-1.0.1
mysql-server - update to 8.0.41-1.0.1
mysql-libs - update to 8.0.41-1.0.1
mysql-errmsg - update to 8.0.41-1.0.1
mysql-devel - update to 8.0.41-1.0.1
mysql-common - update to 8.0.41-1.0.1
mysql - update to 8.0.41-1.0.1
mysql (Red Hat package) - update to 8.0.41-2.el9_5
curl-doc - update to 8.4.0-8
libcurl-minimal - update to 8.4.0-8
libcurl-devel - update to 8.4.0-8
libcurl - update to 8.4.0-8
curl-minimal - update to 8.4.0-8
curl - update to 8.4.0-8
libcurl3t64-gnutls (Ubuntu package) - addressed in versions 8.5.0-2ubuntu10.6, 8.9.1-2ubuntu2.2
libcurl4t64 (Ubuntu package) - addressed in versions 8.5.0-2ubuntu10.6, 8.9.1-2ubuntu2.2
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
SmartFabric OS10 - update to 10.6.0.3
PowerProtect Data Manager - update to 19.19.0-15
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
External References
Related Security Bulletins
- Information disclosure in cURL
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- Ubuntu update for curl
- SUSE update for curl
- Multiple vulnerabilities in cPanel EasyApache
- SUSE update for curl
- openEuler 22.03 LTS SP1 update for curl
- openEuler 22.03 LTS SP3 update for curl
- openEuler 24.03 LTS SP1 update for curl
- openEuler 24.03 LTS update for curl
- openEuler 22.03 LTS SP4 update for curl
- Multiple vulnerabilities in MySQL Server
- MySQL Enterprise Backup update for curl
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Red Hat Enterprise Linux 9 update for mysql
- Red Hat Enterprise Linux 8 update for the mysql:8.0 module
- Dell SmartFabric Manager update for third-party components
- Anolis OS update for mysql:8.0 module
- Dell VxRail Appliance 8.x update for third-party components
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Infrastructure Technology
- Multiple vulnerabilities in Oracle HTTP Server
- Tenable Security Center update for third-party components
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Multiple vulnerabilities in IBM CICS TX Advanced
- Anolis OS update for curl
- Meinberg LANTIME firmware update for third-party components (February 2025)
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell Networking OS10
- Multiple vulnerabilities in Tenable Network Monitor
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Ubuntu update for curl