Expired pointer dereference in cURL - CVE-2020-8231
Published: August 20, 2020
Vulnerability details
The vulnerability allows an attacker to gain access to sensitive information.
The vulnerability exists due to expired pointer dereference error for CURLOPT_CONNECT_ONLY connections that may lead to information disclosure. If the application is using the CURLOPT_CONNECT_ONLY option to check if the website is accessible, an attacker might abuse this feature and force the application to re-use expired connection and send data intended to another connection to attacker controlled server.
Affected software
Cloud Pak for Security (CP4S)
Gentoo Linux
ClevOS
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
Slackware Linux
Ubuntu
Opensuse
openEuler
Fedora
VMware Tanzu Operations Manager
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
OpenShift Virtualization
Isolation Segment
TensorFlow
VMware Tanzu Application Service for VMs
Tanzu Greenplum for Kubernetes
Platform Automation Toolkit
curl (Alpine package)
curl (Red Hat package)
curl (Debian package)
libcurl3-gnutls (Ubuntu package)
libcurl3-nss (Ubuntu package)
curl (Ubuntu package)
libcurl3 (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl4-debuginfo
libcurl4-debuginfo-32bit
libcurl4
libcurl4-32bit
curl-debugsource
curl-debuginfo
curl
libcurl
libcurl-devel
curl-help
Oracle Communications Cloud Native Core Policy
Red Hat OpenShift Jaeger
Splunk Universal Forwarder
Splunk Enterprise
SINEC INS
Web Terminal
How to mitigate CVE-2020-8231
VMware Tanzu Operations Manager - addressed in versions 2.6.27, 2.7.23, 2.8.13, 2.9.10, 2.10.1
Isolation Segment - addressed in versions 2.7.23, 2.8.17, 2.9.11, 2.10.3
Tanzu Greenplum for Kubernetes - update to 2.0.0
Red Hat OpenShift Serverless - update to 1.16.0
TensorFlow - update to 2.5.0
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Windows Container Support for Red Hat OpenShift - update to 2.0.1
VMware Tanzu Application Service for VMs - addressed in versions 2.7.23, 2.8.17, 2.9.11, 2.10.3
Platform Automation Toolkit - addressed in versions 4.1.22, 4.2.17, 4.3.14, 4.4.6
curl (Alpine package) - update to 7.72.0-r0
curl (Red Hat package) - update to 7.61.1-18.el8
curl (Debian package) - update to 7.64.0-4+deb10u2
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
SINEC INS - update to 1.0.1.1
Web Terminal - update to 1.3
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm5, 7.47.0-1ubuntu2.16, 7.47.0-1ubuntu2.18, 7.58.0-2ubuntu3.10, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu2.25, 7.68.0-1ubuntu4.2
libcurl3-nss (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm5, 7.47.0-1ubuntu2.16, 7.47.0-1ubuntu2.18, 7.58.0-2ubuntu3.10, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu2.25, 7.68.0-1ubuntu4.2
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm5, 7.47.0-1ubuntu2.16, 7.47.0-1ubuntu2.18, 7.58.0-2ubuntu3.10, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu2.25, 7.68.0-1ubuntu4.2
libcurl3 (Ubuntu package) - addressed in versions 7.47.0-1ubuntu2.16, 7.47.0-1ubuntu2.18
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.10, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu2.25, 7.68.0-1ubuntu4.2
libcurl4-debuginfo - update to 7.60.0-4.20.1
libcurl4-debuginfo-32bit - update to 7.60.0-4.20.1
libcurl4 - update to 7.60.0-4.20.1
libcurl4-32bit - update to 7.60.0-4.20.1
curl-debugsource - update to 7.60.0-4.20.1
curl-debuginfo - update to 7.60.0-4.20.1
curl - update to 7.60.0-4.20.1
curl - addressed in versions 7.66.0-3.fc31, 7.69.1-5.fc32
libcurl - update to 7.71.1-5
libcurl-devel - update to 7.71.1-5
curl-help - update to 7.71.1-5
curl-debugsource - update to 7.71.1-5
curl - update to 7.71.1-5
curl-debuginfo - update to 7.71.1-5
External References
Related Security Bulletins
- Information disclosure in cURL
- Slackware Linux update for curl
- Expired pointer dereference in curl (Alpine package)
- OpenSUSE Linux update for curl
- OpenSUSE Linux update for curl
- OpenSUSE Linux update for curl
- Information disclosure in several VMware Products
- Amazon Linux AMI update for curl
- Gentoo update for cURL
- Debian update for curl
- Tensorflow update for third-party components
- Red Hat Enterprise Linux 8 update for curl
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in Windows Container Support for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in OpenShift Serverless
- Multiple vulnerabilities in Red Hat Web Terminal
- Multiple vulnerabilities in Siemens SINEC INS
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- SUSE update for curl
- Multiple vulnerabilities in IBM Cloud Pak for Security
- ClevOS update for IBM Cloud Object Storage Systems
- Splunk Universal Forwarder update for third-party packages
- Splunk Enterprise update for third-party packages
- openEuler update for curl
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in OpenShift Virtualization 2.6
- Ubuntu update for curl
- Ubuntu update for curl
- Ubuntu update for curl
- Fedora 32 update for curl
- Fedora 31 update for curl