security advisorycriticalDebian
Viktor Szakats reported that libcurl, an URL transfer library, does not strip off user credentials from the URL when automatically populating the Referer HTTP request header field in outgoing HTTP requests. Sensitive authentication data may leak to the server that is . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2664-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler May 17, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : curl Version : 7.52.1-5+deb9u14 CVE ID : CVE-2021-22876 Debian Bug : 986269 Viktor Szakats reported that libcurl, an URL transfer library, does not strip off user credentials from the URL when automatically populating the Referer HTTP request header field in outgoing HTTP requests. Sensitive authentication data may leak to the server that is the target of the second HTTP request. For Debian 9 stretch, this problem has been fixed in version 7.52.1-5+deb9u14. We recommend that you upgrade your curl packages. For the detailed security status of curl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/curl Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Elevate your curl libraries for Debian LTS to address possible data vulnerabilities in HTTP transactions that might expose confidential information.. curl security update, Debian security advisory, HTTP authentication leak, libcurl vulnerability. . Severity: Critical. LinuxSecurity.com Team
May 17, 2021
•Critical
Debian LTS