Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Critical Curl Vulnerabilities in Ubuntu 16.04 and 14.04 USN-5894-1

ubuntu
Calendar Grey February 27, 2023
Scroller Ubuntu
Several vulnerabilities identified in curl have been resolved in Ubuntu Security Notice USN-5894-1. Instructions for updating your system are included.
Several security issues were fixed in curl.

Summary

Several security issues were fixed in curl.

Software Description:

- curl: HTTP, HTTPS, and FTP client and client libraries

Details:

Harry Sintonen and Tomas Hoger discovered that curl incorrectly handled

TELNET connections when the -t option was used on the command line.

Uninitialized data possibly containing sensitive information could be sent

to the remote server, contrary to expectations. This issue was only fixed

in Ubuntu 14.04 ESM. (CVE-2021-22898, CVE-2021-22925)

It was discovered that curl incorrectly handled denials when using HTTP

proxies. A remote attacker could use this issue to cause curl to crash,

resulting in a denial of service, or possibly execute arbitrary code.

(CVE-2022-43552)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
   curl                            7.47.0-1ubuntu2.19+esm7
   libcurl3                        7.47.0-1ubuntu2.19+esm7
   libcurl3-gnutls                 7.47.0-1ubuntu2.19+esm7
   libcurl3-nss                    7.47.0-1ubuntu2.19+esm7

Ubuntu 14.04 ESM:
   curl                            7.35.0-1ubuntu2.20+esm14
   libcurl3                        7.35.0-1ubuntu2.20+esm14
   libcurl3-gnutls                 7.35.0-1ubuntu2.20+esm14
   libcurl3-nss                    7.35.0-1ubuntu2.20+esm14

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5894-1

CVE-2021-22898, CVE-2021-22925, CVE-2022-43552

Severity
critical
Lowest
Low
Medium
High
Critical

February 27, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.