Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Debian: DSA-4881-1 Critical: curl Vulnerabilities Causing Information Leak

debian
Calendar Grey March 31, 2021
Debian Logo
Debian Security Notice DSA-4882-1 discusses php's security flaws, outlining necessary patches and updates for mitigation.
Multiple vulnerabilities were discovered in cURL, an URL transfer library: CVE-2020-8169

Summary

CVE-2020-8169

Marek Szlagor reported that libcurl could be tricked into prepending
a part of the password to the host name before it resolves it,
potentially leaking the partial password over the network and to the
DNS server(s).

CVE-2020-8177

sn reported that curl could be tricked by a malicious server into
overwriting a local file when using th -J (--remote-header-name) and
-i (--include) options in the same command line.

CVE-2020-8231

Marc Aldorasi reported that libcurl might use the wrong connection
when an application using libcurl's multi API sets the option
CURLOPT_CONNECT_ONLY, which could lead to information leaks.

CVE-2020-8284

Varnavas Papaioannou reported that a malicious server could use the
PASV response to trick curl into connecting back to an arbitrary IP
address and port, potentially making curl extract information about
services that are otherwise private and not disclosed.

CVE-2020-8285

xnynx reported that libcurl could run...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: curl
CVE ID: CVE-2020-8169 CVE-2020-8177 CVE-2020-8231 CVE-2020-8284

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here