ALSA-2021:4511
Dashboard / Vulnerabilities / ALSA-2021:4511
ALSA-2021:4511
Summary: Moderate: curl security and bug fix update
Details: The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP. Security Fix(es): * curl: Leak of authentication credentials in URL via automatic Referer (CVE-2021-22876) * curl: TELNET stack contents disclosure (CVE-2021-22898) * curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure (CVE-2021-22925) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
References: https://errata.almalinux.org/8/ALSA-2021-4511.html, https://vulners.com/cve/CVE-2021-22876, https://vulners.com/cve/CVE-2021-22898, https://vulners.com/cve/CVE-2021-22925
Affected packages
Package
Name: curl
Purl: pkg:rpm/almalinux/curl
Affected ranges
Type: ECOSYSTEM
Events:
