Comparison using wrong factors in cURL - CVE-2024-9681
Published: November 6, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to an error in HSTS cache implementation. When curl is asked to use HSTS, the expiry time for a subdomain can overwrite a parent domain's cache entry, making it end sooner or later
than otherwise intended. This can lead to situations when the website becomes unavailable or force the client to switch to HTTP from HTTP connection earlier than intended.
Affected software
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
visionOS
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
watchOS
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
SUSE Linux Enterprise Server 12 SP5 LTSS
macOS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
tvOS
iPadOS
Apple iOS
openEuler
Ubuntu
Fedora
APEX Cloud Platform for Microsoft Azure
Guardium Data Security Center (GDSC)
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect Client
SmartFabric OS10
EasyApache
IBM Safer Payments
Dell Secure Connect Gateway
IBM Rational ClearCase
Nessus Network Monitor
SecurityCenter
LANTIME Operating System Firmware (LTOS)
Dell EMC VxRail Appliance
libcurl-devel
curl
curl-debuginfo
curl-debugsource
libcurl
curl-help
libcurl4 (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
curl (Ubuntu package)
libcurl4-debuginfo-32bit
libcurl4-debuginfo
libcurl4
libcurl4-32bit
libcurl-devel-32bit
libcurl4-32bit-debuginfo
libcurl4-64bit
libcurl-devel-64bit
libcurl4-64bit-debuginfo
libcurl4t64 (Ubuntu package)
libcurl3t64-gnutls (Ubuntu package)
Dell EMC NetWorker vProxy
How to mitigate CVE-2024-9681
visionOS - update to 2.4
APEX Cloud Platform for Microsoft Azure - update to 01.04.00.00
Guardium Data Security Center (GDSC) - update to 3.6.1
EasyApache - update to 4 2024-11-13
Nessus Network Monitor - update to 6.5.1
SecurityCenter - update to SC-202504.2
IBM Safer Payments - addressed in versions 6.4.2.11, 6.5.0.09, 6.6.0.07, 6.7.0.03
LANTIME Operating System Firmware (LTOS) - update to 7.08.018
Dell EMC VxRail Appliance - addressed in versions 7.0.533, 8.320
watchOS - update to 11.4
macOS - addressed in versions 13.7.5 22H527, 14.7.5 23H527, 15.4 24E248
tvOS - update to 18.4
iPadOS - addressed in versions 17.7.6, 18.4 22E240
Apple iOS - update to 18.4 22E240
Dell Secure Connect Gateway - update to 5.28.00.14
libcurl-devel - addressed in versions 7.79.1-33, 8.4.0-11
curl - addressed in versions 7.79.1-33, 8.4.0-11
curl-debuginfo - addressed in versions 7.79.1-33, 8.4.0-11
curl-debugsource - addressed in versions 7.79.1-33, 8.4.0-11
libcurl - addressed in versions 7.79.1-33, 8.4.0-11
curl-help - addressed in versions 7.79.1-33, 8.4.0-11
libcurl4 (Ubuntu package) - update to 7.81.0-1ubuntu1.19
libcurl3-nss (Ubuntu package) - update to 7.81.0-1ubuntu1.19
libcurl3-gnutls (Ubuntu package) - update to 7.81.0-1ubuntu1.19
curl (Ubuntu package) - addressed in versions 7.81.0-1ubuntu1.19, 8.5.0-2ubuntu10.5, 8.9.1-2ubuntu2.1
libcurl4-debuginfo-32bit - update to 8.0.1-11.98.1
libcurl-devel - addressed in versions 8.0.1-11.98.1, 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
curl-debugsource - addressed in versions 8.0.1-11.98.1, 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
curl - addressed in versions 8.0.1-11.98.1, 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl4-debuginfo - addressed in versions 8.0.1-11.98.1, 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl4 - addressed in versions 8.0.1-11.98.1, 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
curl-debuginfo - addressed in versions 8.0.1-11.98.1, 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl4-32bit - addressed in versions 8.0.1-11.98.1, 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl-devel-32bit - addressed in versions 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl4-32bit-debuginfo - addressed in versions 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl4-64bit - addressed in versions 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl-devel-64bit - addressed in versions 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
libcurl4-64bit-debuginfo - addressed in versions 8.0.1-150400.5.56.1, 8.6.0-150600.4.12.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect Client - update to 8.2.1
libcurl4t64 (Ubuntu package) - addressed in versions 8.5.0-2ubuntu10.5, 8.9.1-2ubuntu2.1
libcurl3t64-gnutls (Ubuntu package) - addressed in versions 8.5.0-2ubuntu10.5, 8.9.1-2ubuntu2.1
curl - update to 8.9.1-3.fc41
IBM Rational ClearCase - addressed in versions 9.1.0.8, 10.0.1.3, 11.0.0.3
SmartFabric OS10 - update to 10.6.0.3
Dell EMC NetWorker vProxy - addressed in versions 19.11.0.5, 19.12.0.1
External References
Related Security Bulletins
- Incorrect HSTS cache handling in cURL
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- cPanel EasyApache4 update for cURL
- openEuler 24.03 LTS update for curl
- openEuler 22.03 LTS SP1 update for curl
- Ubuntu update for curl
- openEuler 22.03 LTS SP3 update for curl
- openEuler 22.03 LTS SP4 update for curl
- Fedora 41 update for curl
- SUSE update for curl
- Multiple vulnerabilities in Guardium Data Security Center
- Multiple vulnerabilities in IBM Rational ClearCase
- Multiple vulnerabilities in Dell VxRail Appliance
- Multiple vulnerabilities in Dell VxRail Appliance 7.x
- APEX Cloud Platform for Microsoft Azure update for third-party components
- Multiple vulnerabilities in macOS Sequoia
- Multiple vulnerabilities in macOS Sonoma
- Multiple vulnerabilities in macOS Ventura
- Multiple vulnerabilities in iPadOS 17
- Multiple vulnerabilities in Apple iOS 18 and iPadOS 18
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple visionOS
- Multiple vulnerabilities in Apple watchOS
- Tenable Security Center update for third-party components
- Dell EMC NetWorker vProxy update for third-party components
- Meinberg LANTIME firmware update for third-party components (December 2024)
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell Networking OS10
- Multiple vulnerabilities in Tenable Network Monitor
- IBM Safer Payments update for curl
- Multiple vulnerabilities in IBM Storage Protect Backup-Archive Client, IBM Storage Protect for Virtual Environments and IBM Storage Protect for Space Management