Security features bypass in cURL - CVE-2022-43551

 

Security features bypass in cURL - CVE-2022-43551

Published: December 21, 2022


Vulnerability identifier: #VU70457
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-43551
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to gain access to sensitive information.

The vulnerability exists in the way curl handles IDN characters in hostnames. The HSTS mechanism could be bypassed if the hostname in the given URL first uses IDN characters that get replaced to ASCII counterparts as part of the IDN conversion. Then in a subsequent request it does not detect the HSTS state and makes a clear text transfer.


Affected software

cURL
VMware Tanzu RabbitMQ for VMs
Oracle HTTP Server
IBM Spectrum Copy Data Management
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Safer Payments
IBM QRadar WinCollect Agent
IBM Spectrum Protect Plus
Amazon Linux AMI
PowerSC
Gentoo Linux
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
IBM AIX
Oracle Solaris
macOS
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Ubuntu
openEuler
Fedora
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
cflinuxfs3
Telemetry Dashboard
Liquidware
IBM Engineering Requirements Management DOORS Next
Citrix Workspace App
Webex App VDI
ObjectScale
Platform Automation Toolkit
Dell PowerProtect Cyber Recovery
JBoss Core Services
MySQL Server
LANTIME Operating System Firmware (LTOS)
Splunk Universal Forwarder
Splunk Enterprise
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
libcurl3-nss (Ubuntu package)
curl (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl4 (Ubuntu package)
curl
curl-debuginfo
libcurl-devel
libcurl
curl-debugsource
curl-help
libcurl4-32bit-debuginfo
libcurl4-32bit
libcurl-devel-32bit
libcurl4
libcurl4-debuginfo
jbcs-httpd24-curl (Red Hat package)
mysql-common
mysql-debuginfo
mysql-errmsg
mysql-debugsource
mysql-server
mysql-config
mysql-help
mysql-test
mysql-devel
mysql-libs
mysql
net-misc/curl
SINEC NMS
VMware Tanzu Operations Manager

How to mitigate CVE-2022-43551

Install updates from vendor's website.

cURL - update to 7.87.0
cflinuxfs3 - update to 0.348.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
JBoss Core Services - update to 2.4.51 SP2
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
LANTIME Operating System Firmware (LTOS) - update to 7.06.012
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
macOS - update to 13.3 22E252
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-33.el7jbcs, 0.4.10-33.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-18.el7jbcs, 1.0.0-18.el8jbcs
SINEC NMS - update to 1.0.3.1
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.18-2.el7jbcs, 1.3.18-2.el8jbcs
ObjectScale - update to 1.4.0
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-101.el7jbcs, 1.6.1-101.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-23.el7jbcs, 1.15.19-23.el8jbcs
IBM Spectrum Copy Data Management - update to 2.2.20.1
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.0-20.el7jbcs, 2.4.0-20.el8jbcs
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.51-39.el7jbcs, 2.4.51-39.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-24.el7jbcs, 2.9.3-24.el8jbcs
Isolation Segment - addressed in versions 2.11.27, 2.12.17, 2.13.12, 3.0.7
VMware Tanzu Application Service for VMs - addressed in versions 2.11.33, 2.12.22, 2.13.15, 3.0.7
VMware Tanzu Operations Manager - update to 3.0.4
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24
IBM Safer Payments - addressed in versions 6.4.2.03, 6.5.0.01
libcurl3-nss (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.22, 7.68.0-1ubuntu2.15, 7.81.0-1ubuntu1.7, 7.85.0-1ubuntu0.2
curl (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.22, 7.68.0-1ubuntu2.15, 7.81.0-1ubuntu1.7, 7.85.0-1ubuntu0.2
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.22, 7.68.0-1ubuntu2.15, 7.81.0-1ubuntu1.7, 7.85.0-1ubuntu0.2
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.22, 7.68.0-1ubuntu2.15, 7.81.0-1ubuntu1.7, 7.85.0-1ubuntu0.2
curl - update to 7.79.1-13
curl-debuginfo - update to 7.79.1-13
libcurl-devel - update to 7.79.1-13
libcurl - update to 7.79.1-13
curl-debugsource - update to 7.79.1-13
curl-help - update to 7.79.1-13
curl-debuginfo - update to 7.79.1-150400.5.12.1
curl - update to 7.79.1-150400.5.12.1
curl-debugsource - update to 7.79.1-150400.5.12.1
libcurl4-32bit-debuginfo - update to 7.79.1-150400.5.12.1
libcurl4-32bit - update to 7.79.1-150400.5.12.1
libcurl-devel-32bit - update to 7.79.1-150400.5.12.1
libcurl4 - update to 7.79.1-150400.5.12.1
libcurl4-debuginfo - update to 7.79.1-150400.5.12.1
libcurl-devel - update to 7.79.1-150400.5.12.1
curl - addressed in versions 7.82.0-12.fc36, 7.85.0-5.fc37
curl - update to 7.87.0-2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.0.1-1.el7jbcs, 8.0.1-1.el8jbcs
mysql-common - addressed in versions 8.0.35-1, 8.0.38-1
mysql-debuginfo - addressed in versions 8.0.35-1, 8.0.38-1
mysql-errmsg - addressed in versions 8.0.35-1, 8.0.38-1
mysql-debugsource - addressed in versions 8.0.35-1, 8.0.38-1
mysql-server - addressed in versions 8.0.35-1, 8.0.38-1
mysql-config - addressed in versions 8.0.35-1, 8.0.38-1
mysql-help - addressed in versions 8.0.35-1, 8.0.38-1
mysql-test - addressed in versions 8.0.35-1, 8.0.38-1
mysql-devel - addressed in versions 8.0.35-1, 8.0.38-1
mysql-libs - addressed in versions 8.0.35-1, 8.0.38-1
mysql - addressed in versions 8.0.35-1, 8.0.38-1
net-misc/curl - update to 8.3.0-r2
IBM QRadar WinCollect Agent - update to 10.1.2
IBM Spectrum Protect Plus - update to 10.1.15
Dell PowerProtect Cyber Recovery - update to 19.14.0.1

External References

Related Security Bulletins