Information disclosure in cURL - CVE-2024-11053

 

Information disclosure in cURL - CVE-2024-11053

Published: December 11, 2024


Vulnerability identifier: #VU101654
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-11053
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to an error when using a .netrc file for credentials and an instruction to follow HTTP redirects. The cURL library can leak credentials intended for the first URL prior to redirection. This however will only occur if the .netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.


Affected software

cURL
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
Basesystem Module
openSUSE Leap
openEuler
SmartFabric Manager
EasyApache
Infrastructure Technology
Oracle HTTP Server
APEX Cloud Platform for Red Hat OpenShift
PowerProtect Data Manager
IBM Cloud Pak for Business Automation
Nessus Network Monitor
MySQL Enterprise Backup
Communications Unified Assurance
SecurityCenter
LANTIME Operating System Firmware (LTOS)
Dell EMC VxRail Appliance
MySQL Server
mecab
mecab-ipadic
mecab-ipadic-EUCJP
curl (Ubuntu package)
libcurl4-debuginfo
curl
curl-debugsource
curl-debuginfo
libcurl4
libcurl3-gnutls (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl
libcurl-devel
curl-help
libcurl4-32bit
libcurl4-debuginfo-32bit
libcurl4-32bit-debuginfo
libcurl-devel-64bit
libcurl4-64bit
libcurl4-64bit-debuginfo
libcurl-devel-32bit
mysql-test
mysql-server
mysql-libs
mysql-errmsg
mysql-devel
mysql-common
mysql
mysql (Red Hat package)
curl-doc
libcurl-minimal
curl-minimal
libcurl3t64-gnutls (Ubuntu package)
libcurl4t64 (Ubuntu package)
Dell EMC Storage Monitoring and Reporting (SMR)
Storage Resource Manager
SmartFabric OS10
IBM CICS TX Advanced

How to mitigate CVE-2024-11053

Install updates from vendor's website.

cURL - update to 8.11.1
SmartFabric Manager - update to 1.2.0
EasyApache - update to 4 2024-12-18
Nessus Network Monitor - update to 6.5.1
SecurityCenter - update to SC-202504.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.020
Dell EMC VxRail Appliance - update to 8.321
MySQL Server - addressed in versions 8.0.41, 8.4.4, 9.2.0
MySQL Enterprise Backup - addressed in versions 8.0.41, 8.4.4, 9.2.0
mecab - update to 0.996-2
mecab-ipadic - update to 2.7.0.20070801-17.0.1
mecab-ipadic-EUCJP - update to 2.7.0.20070801-17.0.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm21, 7.47.0-1ubuntu2.19+esm17, 7.58.0-2ubuntu3.24+esm10, 7.68.0-1ubuntu2.25, 7.68.0-1ubuntu2.25+esm5, 7.81.0-1ubuntu1.20, 8.5.0-2ubuntu10.6, 8.5.0-2ubuntu10.11, 8.9.1-2ubuntu2.2, 8.14.1-2ubuntu1.5, 8.18.0-1ubuntu2.3
libcurl4-debuginfo - addressed in versions 7.66.0-150200.4.81.1, 8.0.1-11.101.1, 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
curl - addressed in versions 7.66.0-150200.4.81.1, 8.0.1-11.101.1, 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
curl-debugsource - addressed in versions 7.66.0-150200.4.81.1, 8.0.1-11.101.1, 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
curl-debuginfo - addressed in versions 7.66.0-150200.4.81.1, 8.0.1-11.101.1, 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl4 - addressed in versions 7.66.0-150200.4.81.1, 8.0.1-11.101.1, 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.25, 7.81.0-1ubuntu1.20
libcurl3-nss (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.25, 7.81.0-1ubuntu1.20
libcurl4 (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.25, 7.81.0-1ubuntu1.20
curl-debugsource - addressed in versions 7.79.1-36, 8.4.0-14
libcurl - addressed in versions 7.79.1-36, 8.4.0-14
curl-debuginfo - addressed in versions 7.79.1-36, 8.4.0-14
libcurl-devel - addressed in versions 7.79.1-36, 8.4.0-14
curl - addressed in versions 7.79.1-36, 8.4.0-14
curl-help - addressed in versions 7.79.1-36, 8.4.0-14
libcurl4-32bit - addressed in versions 8.0.1-11.101.1, 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl4-debuginfo-32bit - update to 8.0.1-11.101.1
libcurl-devel - addressed in versions 8.0.1-11.101.1, 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl4-32bit-debuginfo - addressed in versions 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl-devel-64bit - addressed in versions 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl4-64bit - addressed in versions 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl4-64bit-debuginfo - addressed in versions 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
libcurl-devel-32bit - addressed in versions 8.0.1-150400.5.59.1, 8.6.0-150600.4.15.1
mysql-test - update to 8.0.41-1.0.1
mysql-server - update to 8.0.41-1.0.1
mysql-libs - update to 8.0.41-1.0.1
mysql-errmsg - update to 8.0.41-1.0.1
mysql-devel - update to 8.0.41-1.0.1
mysql-common - update to 8.0.41-1.0.1
mysql - update to 8.0.41-1.0.1
mysql (Red Hat package) - update to 8.0.41-2.el9_5
curl-doc - update to 8.4.0-8
libcurl-minimal - update to 8.4.0-8
libcurl-devel - update to 8.4.0-8
libcurl - update to 8.4.0-8
curl-minimal - update to 8.4.0-8
curl - update to 8.4.0-8
libcurl3t64-gnutls (Ubuntu package) - addressed in versions 8.5.0-2ubuntu10.6, 8.9.1-2ubuntu2.2
libcurl4t64 (Ubuntu package) - addressed in versions 8.5.0-2ubuntu10.6, 8.9.1-2ubuntu2.2
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
SmartFabric OS10 - update to 10.6.0.3
PowerProtect Data Manager - update to 19.19.0-15
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1

External References

Related Security Bulletins