Security features bypass in cURL - CVE-2022-43551
Published: December 21, 2022
Vulnerability details
The vulnerability allows an attacker to gain access to sensitive information.
The vulnerability exists in the way curl handles IDN characters in hostnames. The HSTS mechanism could be bypassed if the hostname in the given URL first uses IDN characters that get replaced to ASCII counterparts as part of the IDN conversion. Then in a subsequent request it does not detect the HSTS state and makes a clear text transfer.
Affected software
VMware Tanzu RabbitMQ for VMs
Oracle HTTP Server
IBM Spectrum Copy Data Management
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Safer Payments
IBM QRadar WinCollect Agent
IBM Spectrum Protect Plus
Amazon Linux AMI
PowerSC
Gentoo Linux
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
IBM AIX
Oracle Solaris
macOS
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Ubuntu
openEuler
Fedora
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
cflinuxfs3
Telemetry Dashboard
Liquidware
IBM Engineering Requirements Management DOORS Next
Citrix Workspace App
Webex App VDI
ObjectScale
Platform Automation Toolkit
Dell PowerProtect Cyber Recovery
JBoss Core Services
MySQL Server
LANTIME Operating System Firmware (LTOS)
Splunk Universal Forwarder
Splunk Enterprise
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
libcurl3-nss (Ubuntu package)
curl (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl4 (Ubuntu package)
curl
curl-debuginfo
libcurl-devel
libcurl
curl-debugsource
curl-help
libcurl4-32bit-debuginfo
libcurl4-32bit
libcurl-devel-32bit
libcurl4
libcurl4-debuginfo
jbcs-httpd24-curl (Red Hat package)
mysql-common
mysql-debuginfo
mysql-errmsg
mysql-debugsource
mysql-server
mysql-config
mysql-help
mysql-test
mysql-devel
mysql-libs
mysql
net-misc/curl
SINEC NMS
VMware Tanzu Operations Manager
How to mitigate CVE-2022-43551
cflinuxfs3 - update to 0.348.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
JBoss Core Services - update to 2.4.51 SP2
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
LANTIME Operating System Firmware (LTOS) - update to 7.06.012
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
macOS - update to 13.3 22E252
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-33.el7jbcs, 0.4.10-33.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-18.el7jbcs, 1.0.0-18.el8jbcs
SINEC NMS - update to 1.0.3.1
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.18-2.el7jbcs, 1.3.18-2.el8jbcs
ObjectScale - update to 1.4.0
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-101.el7jbcs, 1.6.1-101.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-23.el7jbcs, 1.15.19-23.el8jbcs
IBM Spectrum Copy Data Management - update to 2.2.20.1
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.0-20.el7jbcs, 2.4.0-20.el8jbcs
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.51-39.el7jbcs, 2.4.51-39.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-24.el7jbcs, 2.9.3-24.el8jbcs
Isolation Segment - addressed in versions 2.11.27, 2.12.17, 2.13.12, 3.0.7
VMware Tanzu Application Service for VMs - addressed in versions 2.11.33, 2.12.22, 2.13.15, 3.0.7
VMware Tanzu Operations Manager - update to 3.0.4
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24
IBM Safer Payments - addressed in versions 6.4.2.03, 6.5.0.01
libcurl3-nss (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.22, 7.68.0-1ubuntu2.15, 7.81.0-1ubuntu1.7, 7.85.0-1ubuntu0.2
curl (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.22, 7.68.0-1ubuntu2.15, 7.81.0-1ubuntu1.7, 7.85.0-1ubuntu0.2
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.22, 7.68.0-1ubuntu2.15, 7.81.0-1ubuntu1.7, 7.85.0-1ubuntu0.2
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.22, 7.68.0-1ubuntu2.15, 7.81.0-1ubuntu1.7, 7.85.0-1ubuntu0.2
curl - update to 7.79.1-13
curl-debuginfo - update to 7.79.1-13
libcurl-devel - update to 7.79.1-13
libcurl - update to 7.79.1-13
curl-debugsource - update to 7.79.1-13
curl-help - update to 7.79.1-13
curl-debuginfo - update to 7.79.1-150400.5.12.1
curl - update to 7.79.1-150400.5.12.1
curl-debugsource - update to 7.79.1-150400.5.12.1
libcurl4-32bit-debuginfo - update to 7.79.1-150400.5.12.1
libcurl4-32bit - update to 7.79.1-150400.5.12.1
libcurl-devel-32bit - update to 7.79.1-150400.5.12.1
libcurl4 - update to 7.79.1-150400.5.12.1
libcurl4-debuginfo - update to 7.79.1-150400.5.12.1
libcurl-devel - update to 7.79.1-150400.5.12.1
curl - addressed in versions 7.82.0-12.fc36, 7.85.0-5.fc37
curl - update to 7.87.0-2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.0.1-1.el7jbcs, 8.0.1-1.el8jbcs
mysql-common - addressed in versions 8.0.35-1, 8.0.38-1
mysql-debuginfo - addressed in versions 8.0.35-1, 8.0.38-1
mysql-errmsg - addressed in versions 8.0.35-1, 8.0.38-1
mysql-debugsource - addressed in versions 8.0.35-1, 8.0.38-1
mysql-server - addressed in versions 8.0.35-1, 8.0.38-1
mysql-config - addressed in versions 8.0.35-1, 8.0.38-1
mysql-help - addressed in versions 8.0.35-1, 8.0.38-1
mysql-test - addressed in versions 8.0.35-1, 8.0.38-1
mysql-devel - addressed in versions 8.0.35-1, 8.0.38-1
mysql-libs - addressed in versions 8.0.35-1, 8.0.38-1
mysql - addressed in versions 8.0.35-1, 8.0.38-1
net-misc/curl - update to 8.3.0-r2
IBM QRadar WinCollect Agent - update to 10.1.2
IBM Spectrum Protect Plus - update to 10.1.15
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- SUSE update for curl
- Multiple vulnerabilities in cflinuxfs3
- Ubuntu update for curl
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- Multiple vulnerabilities in macOS Ventura
- Multiple vulnerabilities in Oracle HTTP Server
- Multiple vulnerabilities in MySQL Server
- IBM Safer Payments update for cURL
- Multiple vulnerabilities in Siemens SINEC NMS
- VMware Tanzu products update for curl
- Splunk Universal Forwarder update for third-party packages
- Red Hat JBoss Core Services update for Apache HTTP Server
- Multiple vulnerabilities in IBM PowerSC
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in Oracle Solaris third-party software
- IBM AIX update for cURL
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in IBM Spectrum Copy Data Management
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in Oracle Solaris third-party software
- Splunk Enterprise update for third-party packages
- Gentoo update for curl
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- openEuler 22.03 LTS update for curl
- openEuler 22.03 LTS SP1 update for mysql
- openEuler 22.03 LTS SP2 update for mysql
- openEuler 22.03 LTS update for mysql
- Multiple vulnerabilities in Dell ThinOS
- Amazon Linux AMI update for curl
- Multiple vulnerabilities in Dell ObjectScale
- openEuler 20.03 LTS SP4 update for mysql
- Fedora 36 update for curl
- Fedora 37 update for curl
- Multiple vulnerabilities in Meinberg LANTIME firmware