Double Free in cURL - CVE-2021-22945

 

Double Free in cURL - CVE-2021-22945

Published: September 15, 2021


Vulnerability identifier: #VU56610
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22945
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when sending data to an MQTT server. A remote attacker with ability to control libcurl input can trigger a double free error and perform a denial of service (DoS) attack.


Affected software

cURL
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
cflinuxfs3
Gentoo Linux
macOS
Slackware Linux
Ubuntu
openEuler
Fedora
My Cloud OS 5
WD Cloud
My Cloud EX2100
My Cloud DL4100
My Cloud DL2100
My Cloud Mirror G2
My Cloud EX2 Ultra
My Cloud EX4100
My Cloud PR4100
My Cloud PR2100
My Cloud
Data Lakehouse
EasyApache
IBM QRadar WinCollect Agent
IBM Spectrum Protect Plus
IBM Cloud Private
Splunk Universal Forwarder
Splunk Enterprise
SINEC INS
curl (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl-devel
libcurl
curl
curl-debugsource
curl-debuginfo
curl-help
curl (Debian package)
net-misc/curl

How to mitigate CVE-2021-22945

Install updates from vendor's website.

cURL - update to 7.79.0
cflinuxfs3 - update to 0.257.0
Data Lakehouse - update to 1.1.0.0
IBM Cloud Private - addressed in versions 3.2.1.2203, 3.2.2.2203
EasyApache - update to 4 2021-9-22
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM QRadar WinCollect Agent - update to 10.0.2
macOS - update to 12.3 21E230
SINEC INS - update to 1.0.1.1
My Cloud OS 5 - update to 5.25.124
curl (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.15, 7.58.0-2ubuntu3.16, 7.68.0-1ubuntu2.7, 7.74.0-1ubuntu2.3
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.15, 7.58.0-2ubuntu3.16, 7.68.0-1ubuntu2.7, 7.74.0-1ubuntu2.3
libcurl3-nss (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.15, 7.58.0-2ubuntu3.16, 7.68.0-1ubuntu2.7, 7.74.0-1ubuntu2.3
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.15, 7.58.0-2ubuntu3.16, 7.68.0-1ubuntu2.7, 7.74.0-1ubuntu2.3
libcurl-devel - update to 7.71.1-11
libcurl - update to 7.71.1-11
curl - update to 7.71.1-11
curl-debugsource - update to 7.71.1-11
curl-debuginfo - update to 7.71.1-11
curl-help - update to 7.71.1-11
curl - addressed in versions 7.71.1-11.fc33, 7.76.1-12.fc34, 7.79.0-4.fc35, 7.79.1-1.fc35
curl (Debian package) - update to 7.74.0-1.3+deb11u2
net-misc/curl - update to 7.86.0
IBM Spectrum Protect Plus - update to 10.1.12

External References

Related Security Bulletins