[USN-5079-3] curl vulnerabilities
marc.deslauriers at canonical.com
Tue Sep 21 12:37:57 UTC 2021
Ubuntu Security Notice USN-5079-3
September 21, 2021
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
USN-5079-1 introduced a regression in curl.
- curl: HTTP, HTTPS, and FTP client and client libraries
USN-5079-1 fixed vulnerabilities in curl. One of the fixes introduced a
regression on Ubuntu 18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that curl incorrect handled memory when sending data to
an MQTT server. A remote attacker could use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
Patrick Monnerat discovered that curl incorrectly handled responses
received before STARTTLS. A remote attacker could possibly use this issue
to inject responses and intercept communications. (CVE-2021-22947)
The problem can be corrected by updating your system to the following
Ubuntu 18.04 LTS:
In general, a standard system update will make all the necessary changes.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: OpenPGP digital signature
More information about the ubuntu-security-announce