Use of Uninitialized Variable in cURL - CVE-2021-22925
Published: July 21, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to usage of uninitialized variable in code, responsible for processing TELNET requests when parsing NEW_ENV variables. A remote attacker can force the affected application to connect to a telnet server under attackers control and read up to 1800 bytes from the uninitialized memory on the libcurl client system.
Affected software
Cloud Pak for Security (CP4S)
Gentoo Linux
Arch Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
macOS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
VMware Tanzu Application Service for VMs
Isolation Segment
EasyApache
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Transformation Advisor
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat OpenStack
cflinuxfs3
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Watson Studio on Cloud Pak for Data
curl (Red Hat package)
curl (Ubuntu package)
libcurl3 (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl4-openssl1-x86
libcurl4-openssl1-32bit
libcurl4-openssl1
curl-openssl1
libcurl4 (Ubuntu package)
libcurl4-32bit-debuginfo
curl
curl-debuginfo
libcurl4-32bit
curl-debugsource
libcurl-devel
libcurl4-debuginfo
libcurl4
libcurl4-debuginfo-32bit
curl-help
libcurl
net-misc/curl
Splunk Universal Forwarder
Splunk Enterprise
SINEC INS
SINEMA Remote Connect Server
Migration Toolkit for Containers
Red Hat OpenShift Serverless
VMware Tanzu Operations Manager
Dell EMC VxRail Appliance
How to mitigate CVE-2021-22925
cflinuxfs3 - update to 0.250.0
Cloud Pak for Security (CP4S) - update to 1.10.7.0
EasyApache - update to 4 2021-7-28
curl (Red Hat package) - update to 7.61.1-22.el8
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
macOS - addressed in versions 10.15.7 19H1417, 11.6 20G165
curl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.47.01ubuntu2.19+esm3, 7.58.0-2ubuntu3.14, 7.68.0-1ubuntu2.6, 7.74.0-1ubuntu2.1
libcurl3 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.47.01ubuntu2.19+esm3
libcurl3-nss (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.47.01ubuntu2.19+esm3, 7.58.0-2ubuntu3.14, 7.68.0-1ubuntu2.6, 7.74.0-1ubuntu2.1
libcurl3-gnutls (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.47.01ubuntu2.19+esm3, 7.58.0-2ubuntu3.14, 7.68.0-1ubuntu2.6, 7.74.0-1ubuntu2.1
SINEC INS - update to 1.0.1.1
Migration Toolkit for Containers - update to 1.5.4
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
VMware Tanzu Operations Manager - update to 2.10.55
SINEMA Remote Connect Server - update to 3.1
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
Watson Studio on Cloud Pak for Data - update to 5.0.3
Dell EMC VxRail Appliance - update to 7.0.203
libcurl4-openssl1-x86 - update to 7.37.0-70.71.1
libcurl4-openssl1-32bit - update to 7.37.0-70.71.1
libcurl4-openssl1 - update to 7.37.0-70.71.1
curl-openssl1 - update to 7.37.0-70.71.1
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.14, 7.68.0-1ubuntu2.6, 7.74.0-1ubuntu2.1
libcurl4-32bit-debuginfo - addressed in versions 7.60.0-3.47.1, 7.66.0-4.22.1
curl - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
curl-debuginfo - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
libcurl4-32bit - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
curl-debugsource - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
libcurl-devel - addressed in versions 7.60.0-3.47.1, 7.60.0-11.23.1, 7.66.0-4.22.1
libcurl4-debuginfo - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
libcurl4 - addressed in versions 7.60.0-3.47.1, 7.60.0-4.25.1, 7.60.0-11.23.1, 7.66.0-4.22.1
libcurl4-debuginfo-32bit - addressed in versions 7.60.0-4.25.1, 7.60.0-11.23.1
curl-help - update to 7.71.1-10
libcurl-devel - update to 7.71.1-10
curl-debugsource - update to 7.71.1-10
libcurl - update to 7.71.1-10
curl - update to 7.71.1-10
curl-debuginfo - update to 7.71.1-10
curl - addressed in versions 7.71.1-10.fc33, 7.76.1-7.fc34
net-misc/curl - update to 7.86.0
Red Hat OpenStack - update to 16.2
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Slackware Linux update for curl
- Arch Linux update for libcurl-compat
- Arch Linux update for lib32-curl
- Arch Linux update for curl
- Arch Linux update for lib32-libcurl-compat
- Arch Linux update for libcurl-gnutls
- Arch Linux update for lib32-libcurl-gnutls
- cPanel EasyApache 4 update for libcurl
- Multiple vulnerabilities in Cloud Foundry cflinuxfs3
- Multiple vulnerabilities in Apple macOS Big Sur
- Remote code execution in Apple macOS Catalina
- Red Hat Enterprise Linux 8 update for curl
- Multiple vulnerabilities in Siemens SINEC INS
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- Multiple vulnerabilities in Siemens SINEMA Remote Connect Server
- Ubuntu update for curl
- Ubuntu update for curl
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Gentoo update for curl
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Ubuntu update for curl
- VMware Tanzu products update for curl
- Splunk Universal Forwarder update for third-party packages
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- openEuler update for curl
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.20
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Migration Toolkit for Containers 1.5
- Fedora 34 update for curl
- Fedora 33 update for curl
- Multiple vulnerabilities in IBM Watson Studio on Cloud Pak for Data - Execution Engine for Apache Hadoop
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2