Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30715
HistoryMay 28, 2021 - 12:59 p.m.

Information Disclosure

2021-05-2812:59:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19
curl
version 7.77.0
telnetoptions
disclosure
sensitive information
network protocol

EPSS

0.002

Percentile

58.3%

A security issue has been found in curl before version 7.77.0. curl supports the -t command line option, known as CURLOPT_TELNETOPTIONS in libcurl. This rarely used option is used to send variable=content pairs to TELNET servers. Due to flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server. Therefore potentially revealing sensitive internal information to the server using a clear-text network protocol.

References