Lucene search

K
osvGoogleOSV:USN-5079-4
HistorySep 21, 2021 - 1:07 p.m.

curl regression

2021-09-2113:07:33
Google
osv.dev
4

9.4 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.9%

USN-5079-2 fixed vulnerabilities in curl. One of the fixes introduced a
regression. This update fixes the problem.

Original advisory details:

Patrick Monnerat discovered that curl incorrectly handled upgrades to TLS.
When receiving certain responses from servers, curl would continue without
TLS even when the option to require a successful upgrade to TLS was
specified. (CVE-2021-22946)

Patrick Monnerat discovered that curl incorrectly handled responses
received before STARTTLS. A remote attacker could possibly use this issue
to inject responses and intercept communications. (CVE-2021-22947)