Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Ubuntu 16.04 ESM USN-5021-2 Moderate: Curl Info Exposure

Ubuntu Large Esm H500
curl could be made to expose sensitive information if it received a specially crafted input.
=========================================================================Ubuntu Security Notice USN-5021-2
January 20, 2022

curl vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM

Summary:

curl could be made to expose sensitive information if it received a
specially crafted input.

Software Description:
- curl: HTTP, HTTPS, and FTP client and client libraries

Details:

USN-5021-1 fixed vulnerabilities in curl. This update provides
the corresponding updates for Ubuntu 16.04 ESM.

Original advisory details:

Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled
TELNET connections when the -t option was used on the command line.
Uninitialized data possibly containing sensitive information could be sent
to the remote server, contrary to expectations. (CVE-2021-22898,
CVE-2021-22925)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
curl 7.47.0-1ubuntu2.19+esm3
libcurl3 7.47.0-1ubuntu2.19+esm3
libcurl3-gnutls 7.47.0-1ubuntu2.19+esm3
libcurl3-nss 7.47.0-1ubuntu2.19+esm3

In general, a standard system update will make all the necessary changes.

References:


CVE-2021-22898, CVE-2021-22925

Ubuntu 16.04 ESM USN-5021-2 Moderate: Curl Info Exposure

ubuntu
Calendar Grey January 20, 2022
Dist Ubuntu Esm H88
A critical curl vulnerability on Ubuntu may lead to unauthorized access to sensitive info. Users should update to secure their systems promptly
curl could be made to expose sensitive information if it received a specially crafted input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: curl 7.47.0-1ubuntu2.19+esm3 libcurl3 7.47.0-1ubuntu2.19+esm3 libcurl3-gnutls 7.47.0-1ubuntu2.19+esm3 libcurl3-nss 7.47.0-1ubuntu2.19+esm3 In general, a standard system update will make all the necessary changes.

References

CVE-2021-22898, CVE-2021-22925

January 20, 2022

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here