Information disclosure in cURL - CVE-2025-0167
Published: February 5, 2025
Vulnerability identifier: #VU103648
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2025-0167
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to application can leak credentials when asked to use a .netrc file for credentials and to follow HTTP redirects. A remote attacker can gain access to sensitive information.
Affected software
cURL
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Slackware Linux
Basesystem Module
openSUSE Leap
Ubuntu
Anolis OS
EasyApache
APEX Cloud Platform for Red Hat OpenShift
Dell Secure Connect Gateway
PowerProtect Data Manager
Nessus Network Monitor
SecurityCenter
LANTIME Operating System Firmware (LTOS)
RSA Authentication Manager
SmartFabric Manager
Splunk Enterprise
Dell EMC NetWorker vProxy
APEX Cloud Platform for Microsoft Azure
Storage Resource Manager
SmartFabric OS10
Dell EMC Storage Monitoring and Reporting (SMR)
libcurl4-32bit
libcurl4-32bit-debuginfo
libcurl-devel
curl
curl-debugsource
libcurl4
curl-debuginfo
libcurl4-debuginfo
curl (Ubuntu package)
libcurl4-debuginfo-32bit
libcurl4-64bit-debuginfo
libcurl-devel-32bit
libcurl4-64bit
libcurl-devel-64bit
curl-doc
libcurl-minimal
libcurl
curl-minimal
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Slackware Linux
Basesystem Module
openSUSE Leap
Ubuntu
Anolis OS
EasyApache
APEX Cloud Platform for Red Hat OpenShift
Dell Secure Connect Gateway
PowerProtect Data Manager
Nessus Network Monitor
SecurityCenter
LANTIME Operating System Firmware (LTOS)
RSA Authentication Manager
SmartFabric Manager
Splunk Enterprise
Dell EMC NetWorker vProxy
APEX Cloud Platform for Microsoft Azure
Storage Resource Manager
SmartFabric OS10
Dell EMC Storage Monitoring and Reporting (SMR)
libcurl4-32bit
libcurl4-32bit-debuginfo
libcurl-devel
curl
curl-debugsource
libcurl4
curl-debuginfo
libcurl4-debuginfo
curl (Ubuntu package)
libcurl4-debuginfo-32bit
libcurl4-64bit-debuginfo
libcurl-devel-32bit
libcurl4-64bit
libcurl-devel-64bit
curl-doc
libcurl-minimal
libcurl
curl-minimal
How to mitigate CVE-2025-0167
Install updates from vendor's website.
cURL - update to 8.12.0
EasyApache - update to 4 25-5
Nessus Network Monitor - update to 6.5.1
SecurityCenter - update to SC-202504.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.021
RSA Authentication Manager - update to 8.7 SP2 Patch 6
Splunk Enterprise - addressed in versions 9.2.8, 9.3.6, 9.4.4, 10.0.1
Dell EMC NetWorker vProxy - addressed in versions 19.11.0.6, 19.12.0.2
SmartFabric Manager - update to 1.3.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
Dell Secure Connect Gateway - update to 5.28.00.14
libcurl4-32bit - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-11.105.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
libcurl4-32bit-debuginfo - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
libcurl-devel - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-11.105.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
curl - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-11.105.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
curl-debugsource - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-11.105.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
libcurl4 - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-11.105.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
curl-debuginfo - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-11.105.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
libcurl4-debuginfo - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-11.105.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
curl (Ubuntu package) - addressed in versions 7.81.0-1ubuntu1.23, 8.5.0-2ubuntu10.8, 8.14.1-2ubuntu1.2
libcurl4-debuginfo-32bit - update to 8.0.1-11.105.1
libcurl4-64bit-debuginfo - addressed in versions 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
libcurl-devel-32bit - addressed in versions 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
libcurl4-64bit - addressed in versions 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
libcurl-devel-64bit - addressed in versions 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
curl-doc - update to 8.4.0-8
libcurl-minimal - update to 8.4.0-8
libcurl-devel - update to 8.4.0-8
libcurl - update to 8.4.0-8
curl - update to 8.4.0-8
curl-minimal - update to 8.4.0-8
curl - update to 8.12.0
SmartFabric OS10 - update to 10.6.0.3
PowerProtect Data Manager - update to 19.19.0-15
EasyApache - update to 4 25-5
Nessus Network Monitor - update to 6.5.1
SecurityCenter - update to SC-202504.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.021
RSA Authentication Manager - update to 8.7 SP2 Patch 6
Splunk Enterprise - addressed in versions 9.2.8, 9.3.6, 9.4.4, 10.0.1
Dell EMC NetWorker vProxy - addressed in versions 19.11.0.6, 19.12.0.2
SmartFabric Manager - update to 1.3.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
Dell Secure Connect Gateway - update to 5.28.00.14
libcurl4-32bit - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-11.105.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
libcurl4-32bit-debuginfo - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
libcurl-devel - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-11.105.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
curl - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-11.105.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
curl-debugsource - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-11.105.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
libcurl4 - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-11.105.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
curl-debuginfo - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-11.105.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
libcurl4-debuginfo - addressed in versions 7.66.0-150200.4.84.1, 8.0.1-11.105.1, 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
curl (Ubuntu package) - addressed in versions 7.81.0-1ubuntu1.23, 8.5.0-2ubuntu10.8, 8.14.1-2ubuntu1.2
libcurl4-debuginfo-32bit - update to 8.0.1-11.105.1
libcurl4-64bit-debuginfo - addressed in versions 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
libcurl-devel-32bit - addressed in versions 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
libcurl4-64bit - addressed in versions 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
libcurl-devel-64bit - addressed in versions 8.0.1-150400.5.62.1, 8.6.0-150600.4.21.1
curl-doc - update to 8.4.0-8
libcurl-minimal - update to 8.4.0-8
libcurl-devel - update to 8.4.0-8
libcurl - update to 8.4.0-8
curl - update to 8.4.0-8
curl-minimal - update to 8.4.0-8
curl - update to 8.12.0
SmartFabric OS10 - update to 10.6.0.3
PowerProtect Data Manager - update to 19.19.0-15
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Slackware Linux update for curl
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- Multiple vulnerabilities in cPanel EasyApache
- Tenable Security Center update for third-party components
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- RSA Authentication Manager update for third-party components
- Anolis OS update for curl
- Meinberg LANTIME firmware update for third-party components (March 2025)
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell Networking OS10
- Multiple vulnerabilities in Tenable Network Monitor
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Dell SmartFabric Manager update for third-party components
- Dell EMC NetWorker vProxy update for third-party components
- Splunk Enterprise Security update for third-party components
- Ubuntu update for curl