Insufficient verification of data authenticity in cURL - CVE-2021-22947
Published: September 15, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists in the way libcurl handles the STARTTLS negotiation process. When curl connects to an IMAP, POP3, SMTP or FTP server to exchange data securely using STARTTLS to upgrade the connection to TLS level, the server can still respond and send back multiple responses before the TLS upgrade. Such multiple "pipelined" responses are cached by curl. curl would then upgrade to TLS but not flush the in-queue of cached responses and instead use and trust the responses it got before the TLS handshake as if they were authenticated.
Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server.
Over POP3 and IMAP an attacker can inject fake response data.
Affected software
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Microsoft Windows
SUSE Linux Enterprise Server
macOS
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
Windows Server
My Cloud OS 5
WD Cloud
My Cloud EX2100
My Cloud DL4100
My Cloud DL2100
My Cloud Mirror G2
My Cloud EX2 Ultra
My Cloud EX4100
My Cloud PR4100
My Cloud PR2100
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
My Cloud
cflinuxfs3
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Watson Studio on Cloud Pak for Data
Solutions Enabler
Unisphere 360
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
VASA Provider Standalone
Data Lakehouse
Service Telemetry Framework
IBM Spectrum Copy Data Management
EasyApache
IBM QRadar WinCollect Agent
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Spectrum Protect Plus
Juniper Cloud Native Router
curl (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
curl-openssl1
libcurl4-openssl1
libcurl4-openssl1-32bit
libcurl4-openssl1-x86
curl (Ubuntu package)
libcurl3 (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl4-32bit
curl-debugsource
curl
curl-debuginfo
libcurl4-debuginfo
libcurl4-debuginfo-32bit
libcurl4
libcurl-devel
libcurl4-32bit-debuginfo
libcurl-minimal
libcurl
rh-dotnet31-curl (Red Hat package)
curl-help
curl (Debian package)
net-misc/curl
Splunk Universal Forwarder
Splunk Enterprise
SINEC INS
Red Hat OpenShift Serverless
Solutions Enabler Virtual Appliance
Junos cRPD
How to mitigate CVE-2021-22947
cflinuxfs3 - update to 0.257.0
Data Lakehouse - update to 1.1.0.0
IBM Spectrum Copy Data Management - update to 2.2.17
EasyApache - update to 4 2021-9-22
curl (Red Hat package) - addressed in versions 7.61.1-12.el8_2.4, 7.61.1-18.el8_4.2
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM QRadar WinCollect Agent - update to 10.0.2
macOS - update to 12.3 21E230
SINEC INS - update to 1.0.1.1
Red Hat OpenShift Serverless - update to 1.19.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
IBM Cloud Transformation Advisor - update to 3.10.0
DB2 on Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
Watson Studio on Cloud Pak for Data - update to 5.0.3
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.1.0.5.013
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.1.0.5.013
Dell EMC Unity Operating Environment (OE) - update to 5.2.1.0.5.013
My Cloud OS 5 - update to 5.25.124
curl-openssl1 - update to 7.37.0-70.74.1
libcurl4-openssl1 - update to 7.37.0-70.74.1
libcurl4-openssl1-32bit - update to 7.37.0-70.74.1
libcurl4-openssl1-x86 - update to 7.37.0-70.74.1
curl (Ubuntu package) - addressed in versions 7.47.01ubuntu2.19+esm1, 7.47.01ubuntu2.19+esm2, 7.58.0-2ubuntu3.15, 7.58.0-2ubuntu3.16, 7.68.0-1ubuntu2.7, 7.74.0-1ubuntu2.3
libcurl3 (Ubuntu package) - addressed in versions 7.47.01ubuntu2.19+esm1, 7.47.01ubuntu2.19+esm2
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.47.01ubuntu2.19+esm1, 7.47.01ubuntu2.19+esm2, 7.58.0-2ubuntu3.15, 7.58.0-2ubuntu3.16, 7.68.0-1ubuntu2.7, 7.74.0-1ubuntu2.3
libcurl3-nss (Ubuntu package) - addressed in versions 7.47.01ubuntu2.19+esm1, 7.47.01ubuntu2.19+esm2, 7.58.0-2ubuntu3.15, 7.58.0-2ubuntu3.16, 7.68.0-1ubuntu2.7, 7.74.0-1ubuntu2.3
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.15, 7.58.0-2ubuntu3.16, 7.68.0-1ubuntu2.7, 7.74.0-1ubuntu2.3
libcurl4-32bit - addressed in versions 7.60.0-4.30.1, 7.60.0-11.28.1, 7.60.0-25.1
curl-debugsource - addressed in versions 7.60.0-4.30.1, 7.60.0-11.28.1, 7.60.0-25.1
curl - addressed in versions 7.60.0-4.30.1, 7.60.0-11.28.1, 7.60.0-25.1
curl-debuginfo - addressed in versions 7.60.0-4.30.1, 7.60.0-11.28.1, 7.60.0-25.1
libcurl4-debuginfo - addressed in versions 7.60.0-4.30.1, 7.60.0-11.28.1, 7.60.0-25.1
libcurl4-debuginfo-32bit - addressed in versions 7.60.0-4.30.1, 7.60.0-11.28.1
libcurl4 - addressed in versions 7.60.0-4.30.1, 7.60.0-11.28.1, 7.60.0-25.1
libcurl-devel - addressed in versions 7.60.0-11.28.1, 7.60.0-25.1
libcurl4-32bit-debuginfo - update to 7.60.0-25.1
libcurl-minimal - update to 7.61.1-18
libcurl-devel - update to 7.61.1-18
libcurl - update to 7.61.1-18
curl - update to 7.61.1-18
rh-dotnet31-curl (Red Hat package) - update to 7.61.1-22.el7_9
curl-help - update to 7.71.1-11
curl-debuginfo - update to 7.71.1-11
curl-debugsource - update to 7.71.1-11
libcurl-devel - update to 7.71.1-11
libcurl - update to 7.71.1-11
curl - update to 7.71.1-11
curl - addressed in versions 7.71.1-11.fc33, 7.76.1-12.fc34, 7.79.0-4.fc35, 7.79.1-1.fc35
curl (Debian package) - update to 7.74.0-1.3+deb11u2
net-misc/curl - update to 7.86.0
Solutions Enabler Virtual Appliance - addressed in versions 9.1.0.19, 9.2.3.1
Solutions Enabler - addressed in versions 9.1.0.19, 9.2.3.1
Unisphere 360 - addressed in versions 9.1.0.30, 9.2.3.4
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.32, 9.2.3.11
Unisphere for PowerMax - addressed in versions 9.1.0.32, 9.2.3.11
VASA Provider Standalone - addressed in versions 9.1.0.724, 9.2.3.10
IBM Spectrum Protect Plus - update to 10.1.12
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Slackware Linux update for curl
- Multiple vulnerabilities in cflinuxfs3
- Multiple vulnerabilities in cPanel EasyApache
- SUSE MicroOS and Linux Enterprise Module for Basesystem update for curl
- Red Hat Enterprise Linux 8 update for curl
- Amazon Linux AMI update for curl
- Microsoft Windows update for curl
- Red Hat Enterprise Linux 8.2 update for curl
- Multiple vulnerabilities in Siemens SINEC INS
- Multiple vulnerabilities in Apple macOS Monterey
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- Ubuntu update for curl
- Ubuntu update for curl
- Ubuntu update for curl
- Ubuntu update for curl
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- Debian update for curl
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- Multiple vulnerabilities in Red Hat Service Telemetry Framework
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM Spectrum Copy Data Management
- Multiple vulnerabilities in Dell Unisphere for PowerMax, Dell Solutions Enabler, Dell Unisphere 360 and Dell VASA Provider
- Multiple vulnerabilities in Western Digital My Cloud OS 5
- Gentoo update for curl
- .NET Core on Red Hat Enterprise Linux update for rh-dotnet31-curl
- Splunk Universal Forwarder update for third-party packages
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- openEuler update for curl
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.19
- Fedora 35 update for curl
- Fedora 33 update for curl
- Fedora 34 update for curl
- Fedora 35 update for curl
- Multiple vulnerabilities in IBM Watson Studio on Cloud Pak for Data - Execution Engine for Apache Hadoop
- Anolis OS update for curl
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2