Comparison using wrong factors in cURL - CVE-2024-9681

 

Comparison using wrong factors in cURL - CVE-2024-9681

Published: November 6, 2024


Vulnerability identifier: #VU99865
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-9681
CWE-ID: CWE-1025
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to an error in HSTS cache implementation. When curl is asked to use HSTS, the expiry time for a subdomain can overwrite a parent domain's cache entry, making it end sooner or later than otherwise intended. This can lead to situations when the website becomes unavailable or force the client to switch to HTTP from HTTP connection earlier than intended.


Affected software

cURL
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
visionOS
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
watchOS
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
SUSE Linux Enterprise Server 12 SP5 LTSS
macOS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
tvOS
iPadOS
Apple iOS
openEuler
Ubuntu
Fedora
APEX Cloud Platform for Microsoft Azure
Guardium Data Security Center (GDSC)
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect Client
SmartFabric OS10
EasyApache
IBM Safer Payments
Dell Secure Connect Gateway
IBM Rational ClearCase
Nessus Network Monitor
SecurityCenter
LANTIME Operating System Firmware (LTOS)
Dell EMC VxRail Appliance
libcurl-devel
curl
curl-debuginfo
curl-debugsource
libcurl
curl-help
libcurl4 (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
curl (Ubuntu package)
libcurl4-debuginfo-32bit
libcurl4-debuginfo
libcurl4
libcurl4-32bit
libcurl-devel-32bit
libcurl4-32bit-debuginfo
libcurl4-64bit
libcurl-devel-64bit
libcurl4-64bit-debuginfo
libcurl4t64 (Ubuntu package)
libcurl3t64-gnutls (Ubuntu package)
Dell EMC NetWorker vProxy

How to mitigate CVE-2024-9681

Install updates from vendor's website.

cURL - update to 8.11.0
visionOS - update to 2.4
APEX Cloud Platform for Microsoft Azure - update to 01.04.00.00
Guardium Data Security Center (GDSC) - update to 3.6.1
EasyApache - update to 4 2024-11-13
Nessus Network Monitor - update to 6.5.1
SecurityCenter - update to SC-202504.2
IBM Safer Payments - addressed in versions 6.4.2.11, 6.5.0.09, 6.6.0.07, 6.7.0.03
LANTIME Operating System Firmware (LTOS) - update to 7.08.018
Dell EMC VxRail Appliance - addressed in versions 7.0.533, 8.320
watchOS - update to 11.4
macOS - addressed in versions 13.7.5 22H527, 14.7.5 23H527, 15.4 24E248
tvOS - update to 18.4
iPadOS - addressed in versions 17.7.6, 18.4 22E240
Apple iOS - update to 18.4 22E240
Dell Secure Connect Gateway - update to 5.28.00.14
libcurl-devel - addressed in versions 7.79.1-33, 8.4.0-11
curl - addressed in versions 7.79.1-33, 8.4.0-11
curl-debuginfo - addressed in versions 7.79.1-33, 8.4.0-11
curl-debugsource - addressed in versions 7.79.1-33, 8.4.0-11
libcurl - addressed in versions 7.79.1-33, 8.4.0-11
curl-help - addressed in versions 7.79.1-33, 8.4.0-11
libcurl4 (Ubuntu package) - update to 7.81.0-1ubuntu1.19
libcurl3-nss (Ubuntu package) - update to 7.81.0-1ubuntu1.19
libcurl3-gnutls (Ubuntu package) - update to 7.81.0-1ubuntu1.19
curl (Ubuntu package) - addressed in versions 7.81.0-1ubuntu1.19, 8.5.0-2ubuntu10.5, 8.9.1-2ubuntu2.1
libcurl4-debuginfo-32bit - update to 8.0.1-11.98.1
libcurl-devel - addressed in versions 8.0.1-11.98.1, 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
curl-debugsource - addressed in versions 8.0.1-11.98.1, 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
curl - addressed in versions 8.0.1-11.98.1, 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl4-debuginfo - addressed in versions 8.0.1-11.98.1, 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl4 - addressed in versions 8.0.1-11.98.1, 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
curl-debuginfo - addressed in versions 8.0.1-11.98.1, 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl4-32bit - addressed in versions 8.0.1-11.98.1, 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl-devel-32bit - addressed in versions 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl4-32bit-debuginfo - addressed in versions 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl4-64bit - addressed in versions 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl-devel-64bit - addressed in versions 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl4-64bit-debuginfo - addressed in versions 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect Client - update to 8.2.1
libcurl4t64 (Ubuntu package) - addressed in versions 8.5.0-2ubuntu10.5, 8.9.1-2ubuntu2.1
libcurl3t64-gnutls (Ubuntu package) - addressed in versions 8.5.0-2ubuntu10.5, 8.9.1-2ubuntu2.1
curl - update to 8.9.1-3.fc41
IBM Rational ClearCase - addressed in versions 9.1.0.8, 10.0.1.3, 11.0.0.3
SmartFabric OS10 - update to 10.6.0.3
Dell EMC NetWorker vProxy - addressed in versions 19.11.0.5, 19.12.0.1

External References

Related Security Bulletins