Improper certificate validation in cURL - CVE-2024-8096
Published: September 11, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to curl might fail to detect some OCSP problems when configured to use the Certificate Status Request TLS extension. A remote attacker can bypass OCSP stapling protection and perform a Man-in-the-Middle (MitM) attack.
Successful exploitation of the vulnerability requires that curl is build to use GnuTLS library.
Affected software
RecoverPoint for Virtual Machines
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Ubuntu
Basesystem Module
openSUSE Leap
Anolis OS
EasyApache
Oracle HTTP Server
Nessus Network Monitor
SecurityCenter
curl (Ubuntu package)
curl-debuginfo
curl
libcurl4-debuginfo
libcurl4
curl-debugsource
libcurl4 (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl-devel
libcurl4-debuginfo-32bit
libcurl4-32bit
libcurl4-64bit-debuginfo
libcurl4-64bit
libcurl-devel-64bit
libcurl4-32bit-debuginfo
libcurl-devel-32bit
libcurl
curl-minimal
libcurl-minimal
curl-doc
libcurl4t64 (Ubuntu package)
libcurl3t64-gnutls (Ubuntu package)
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for Hyper-V
How to mitigate CVE-2024-8096
EasyApache - update to 4 2024-9-18
Nessus Network Monitor - update to 6.5.0
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
SecurityCenter - update to SC-202504.2
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm21, 7.47.0-1ubuntu2.19+esm17, 7.58.0-2ubuntu3.24+esm10, 7.68.0-1ubuntu2.24, 7.68.0-1ubuntu2.25+esm5, 7.81.0-1ubuntu1.18, 8.5.0-2ubuntu10.4, 8.5.0-2ubuntu10.11, 8.14.1-2ubuntu1.5, 8.18.0-1ubuntu2.3
curl-debuginfo - addressed in versions 7.66.0-150200.4.78.1, 8.0.1-11.92.1, 8.0.1-150400.5.50.1, 8.6.0-150600.4.6.1
curl - addressed in versions 7.66.0-150200.4.78.1, 8.0.1-11.92.1, 8.0.1-150400.5.50.1, 8.6.0-150600.4.6.1
libcurl4-debuginfo - addressed in versions 7.66.0-150200.4.78.1, 8.0.1-11.92.1, 8.0.1-150400.5.50.1, 8.6.0-150600.4.6.1
libcurl4 - addressed in versions 7.66.0-150200.4.78.1, 8.0.1-11.92.1, 8.0.1-150400.5.50.1, 8.6.0-150600.4.6.1
curl-debugsource - addressed in versions 7.66.0-150200.4.78.1, 8.0.1-11.92.1, 8.0.1-150400.5.50.1, 8.6.0-150600.4.6.1
libcurl4 (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.24, 7.81.0-1ubuntu1.18
libcurl3-nss (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.24, 7.81.0-1ubuntu1.18
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.24, 7.81.0-1ubuntu1.18
libcurl-devel - addressed in versions 8.0.1-11.92.1, 8.0.1-150400.5.50.1, 8.6.0-150600.4.6.1
libcurl4-debuginfo-32bit - update to 8.0.1-11.92.1
libcurl4-32bit - addressed in versions 8.0.1-11.92.1, 8.0.1-150400.5.50.1, 8.6.0-150600.4.6.1
libcurl4-64bit-debuginfo - addressed in versions 8.0.1-150400.5.50.1, 8.6.0-150600.4.6.1
libcurl4-64bit - addressed in versions 8.0.1-150400.5.50.1, 8.6.0-150600.4.6.1
libcurl-devel-64bit - addressed in versions 8.0.1-150400.5.50.1, 8.6.0-150600.4.6.1
libcurl4-32bit-debuginfo - addressed in versions 8.0.1-150400.5.50.1, 8.6.0-150600.4.6.1
libcurl-devel-32bit - addressed in versions 8.0.1-150400.5.50.1, 8.6.0-150600.4.6.1
Storage Protect Client - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
libcurl-devel - update to 8.4.0-10
libcurl - update to 8.4.0-10
curl-minimal - update to 8.4.0-10
curl - update to 8.4.0-10
libcurl-minimal - update to 8.4.0-10
curl-doc - update to 8.4.0-10
libcurl4t64 (Ubuntu package) - update to 8.5.0-2ubuntu10.4
libcurl3t64-gnutls (Ubuntu package) - update to 8.5.0-2ubuntu10.4
External References
Related Security Bulletins
- OCSP stapling bypass in cURL
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- Ubuntu update for curl
- Multiple vulnerabilities in Nessus Network Monitor
- cPanel EasyApache update for cURL
- Multiple vulnerabilities in Oracle HTTP Server
- Tenable Security Center update for third-party components
- Dell RecoverPoint for Virtual Machines update for third-party components
- Anolis OS update for curl
- Multiple vulnerabilities in IBM Storage Protect Backup-Archive Client, IBM Storage Protect for Virtual Environments and IBM Storage Protect for Space Management
- Ubuntu update for curl