Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 8: 2021-0438 Moderate: Curl UAF and TLS Bypass Issues

mageia
Calendar Grey September 23, 2021
Dist Mageia Esm H88
Security patch released for curl targeting multiple vulnerabilities, notably UAF and protocol injection flaws in Mageia.
UAF and double-free in MQTT sending

Summary

UAF and double-free in MQTT sending. (CVE-2021-22945)
Protocol downgrade required TLS bypassed. (CVE-2021-22946)
STARTTLS protocol injection via MITM. (CVE-2021-22947)

References

- https://bugs.mageia.org/show_bug.cgi?id=29461

- https://curl.se/docs/CVE-2021-22945.html

- https://curl.se/docs/CVE-2021-22946.html

- https://curl.se/docs/CVE-2021-22947.html

- https://ubuntu.com/security/notices/USN-5079-1

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/J64OFB3I6OV4T3FD3PVSPTCKGUJCXUXX/

- https://www.cve.org/CVERecord?id=CVE-2021-22945

- https://www.cve.org/CVERecord?id=CVE-2021-22946

- https://www.cve.org/CVERecord?id=CVE-2021-22947

Resolution

SRPMS

- 8/core/curl-7.74.0-1.4.mga8

Publication date: 23 Sep 2021
URL: https://advisories.mageia.org/MGASA-2021-0438.html
Type: security
CVE: CVE-2021-22945, CVE-2021-22946, CVE-2021-22947

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here