CURL-CVE-2021-22897
Dashboard / Vulnerabilities / CURL-CVE-2021-22897
Summary: Schannel cipher selection surprise
Details: libcurl lets applications specify which specific TLS ciphers to use in transfers, using the option called `CURLOPT_SSL_CIPHER_LIST`. The cipher selection is used for the TLS negotiation when a transfer is done involving any of the TLS based transfer protocols libcurl supports, such as HTTPS, FTPS, IMAPS, POP3S, SMTPS etc. Due to a mistake in the code, the selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if an application sets up multiple concurrent transfers, the last one that sets the ciphers accidentally controls the set used by all transfers. In a worst-case scenario, this weakens transport security significantly.
References:
Affected packages
Package
Name:
Purl:
Affected ranges
Type: SEMVER
Events:
