Use of uninitialized variable in cURL - CVE-2021-22898

 

Use of uninitialized variable in cURL - CVE-2021-22898

Published: May 26, 2021


Vulnerability identifier: #VU53587
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22898
CWE-ID: CWE-457
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to usage of uninitialized variable in code, responsible for processing TELNET requests when parsing NEW_ENV variables. A remote attacker can force the affected application to connect to a telnet server under attackers control and read up to 1800 bytes from the uninitialized memory on the libcurl client system.

Proof of concept:

curl telnet://example.com -tNEW_ENV=a,bbbbbb (256 'b's)

Affected software

cURL
Cloud Pak for Security (CP4S)
Arch Linux
Amazon Linux AMI
Gentoo Linux
SUSE Manager Server
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
My Cloud OS 5
My Cloud PR2100
My Cloud PR4100
My Cloud EX4100
My Cloud EX2 Ultra
My Cloud Mirror G2
My Cloud DL2100
My Cloud EX2100
My Cloud DL4100
WD Cloud
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
cflinuxfs3
Secured Component Verification (SCV)
IBM MaaS360 Ceriticate Integration Module
IBM MaaS360 Base Module
Isolation Segment
VMware Tanzu Application Service for VMs
EasyApache
Red Hat Advanced Cluster Management for Kubernetes
IBM MaaS360 Cloud Extender Agent
IBM Cloud Transformation Advisor
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat OpenStack
My Cloud
curl (Red Hat package)
curl (Ubuntu package)
libcurl3 (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
curl-openssl1
libcurl4-openssl1
libcurl4-openssl1-32bit
libcurl4-openssl1-x86
curl-debugsource
curl-debuginfo
libcurl-devel
libcurl4-32bit
libcurl4
curl
libcurl4 (Ubuntu package)
libcurl4-32bit-debuginfo
libcurl4-debuginfo
libcurl4-debuginfo-32bit
libcurl
curl-help
curl (Debian package)
Splunk Universal Forwarder
IBM Aspera High-Speed Transfer Server
Splunk Enterprise
SINEC INS
Migration Toolkit for Containers
IBM Aspera High-Speed Transfer Endpoint
IBM Aspera Desktop Client
Red Hat OpenShift Serverless
VMware Tanzu Operations Manager
IBM MaaS360 VPN Module

How to mitigate CVE-2021-22898

Install updates from vendor's website.

cURL - update to 7.77.0
cflinuxfs3 - update to 0.250.0
Cloud Pak for Security (CP4S) - update to 1.10.7.0
EasyApache - update to 4 2021-6-2
curl (Red Hat package) - update to 7.61.1-22.el8
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
curl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.47.01ubuntu2.19+esm3, 7.58.0-2ubuntu3.14, 7.68.0-1ubuntu2.6, 7.74.0-1ubuntu2.1
libcurl3 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.47.01ubuntu2.19+esm3
libcurl3-nss (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.47.01ubuntu2.19+esm3, 7.58.0-2ubuntu3.14, 7.68.0-1ubuntu2.6, 7.74.0-1ubuntu2.1
libcurl3-gnutls (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.47.01ubuntu2.19+esm3, 7.58.0-2ubuntu3.14, 7.68.0-1ubuntu2.6, 7.74.0-1ubuntu2.1
SINEC INS - update to 1.0.1.1
Migration Toolkit for Containers - update to 1.5.4
Red Hat OpenShift Serverless - update to 1.20.0
Secured Component Verification (SCV) - update to 1.92.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
VMware Tanzu Operations Manager - update to 2.10.55
IBM MaaS360 Cloud Extender Agent - update to 2.105.300.005
IBM MaaS360 Ceriticate Integration Module - update to 2.105.300.005
IBM MaaS360 VPN Module - update to 2.105.300.005
IBM MaaS360 Base Module - update to 2.105.300.005
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
IBM Aspera High-Speed Transfer Server - update to 4.2
IBM Aspera High-Speed Transfer Endpoint - update to 4.2
IBM Aspera Desktop Client - update to 4.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
My Cloud OS 5 - update to 5.25.124
curl-openssl1 - addressed in versions 7.37.0-70.63.1, 7.37.0-70.66.1
libcurl4-openssl1 - addressed in versions 7.37.0-70.63.1, 7.37.0-70.66.1
libcurl4-openssl1-32bit - addressed in versions 7.37.0-70.63.1, 7.37.0-70.66.1
libcurl4-openssl1-x86 - addressed in versions 7.37.0-70.63.1, 7.37.0-70.66.1
curl-debugsource - addressed in versions 7.37.0-70.66.1, 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.18.1, 7.66.0-4.17.1
curl-debuginfo - addressed in versions 7.37.0-70.66.1, 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.18.1, 7.66.0-4.17.1
libcurl-devel - addressed in versions 7.37.0-70.66.1, 7.60.0-3.42.1, 7.60.0-11.18.1, 7.66.0-4.17.1
libcurl4-32bit - addressed in versions 7.37.0-70.66.1, 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.18.1, 7.66.0-4.17.1
libcurl4 - addressed in versions 7.37.0-70.66.1, 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.18.1, 7.66.0-4.17.1
curl - addressed in versions 7.37.0-70.66.1, 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.18.1, 7.66.0-4.17.1
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.14, 7.68.0-1ubuntu2.6, 7.74.0-1ubuntu2.1
libcurl4-32bit-debuginfo - addressed in versions 7.60.0-3.42.1, 7.66.0-4.17.1
libcurl4-debuginfo - addressed in versions 7.60.0-3.42.1, 7.60.0-4.20.1, 7.60.0-11.18.1, 7.66.0-4.17.1
libcurl4-debuginfo-32bit - addressed in versions 7.60.0-4.20.1, 7.60.0-11.18.1
libcurl - update to 7.71.1-7
curl-help - update to 7.71.1-7
curl-debuginfo - update to 7.71.1-7
libcurl-devel - update to 7.71.1-7
curl-debugsource - update to 7.71.1-7
curl - update to 7.71.1-7
curl - addressed in versions 7.71.1-10.fc33, 7.76.1-3.fc34, 7.76.1-7.fc34
curl (Debian package) - update to 7.74.0-1.3+deb11u2
Red Hat OpenStack - update to 16.2

External References

Related Security Bulletins