curl: Expired pointer dereference via multi API with CURLOPT_CONNECT_ONLY option set
Published Dec 14, 2020
7.5
HIGHCVSS 3.1
EPSS 3.77%
Description
Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.
Affected products
No data.
Configuration 2
- < 1.0.1.1
Configuration 3
- 10.0
Configuration 4
- 1.14.0
Configuration 5
- ≥ 8.2.0 · < 8.2.12
- ≥ 9.0.0 · < 9.0.6
- 9.1.0
No data.
Red Hat Enterprise Linux 8
curl-0:7.61.1-18.el8
Fixed · RHSA-2021:1610
.NET Core 2.1 on Red Hat Enterprise Linux
rh-dotnet21-curl
Not affected
.NET Core 3.1 on Red Hat Enterprise Linux
rh-dotnet31-curl
Not affected
Red Hat Ceph Storage 2
curl
Out of support scope
Red Hat Enterprise Linux 5
curl
Not affected
Red Hat Enterprise Linux 6
curl
Not affected
Red Hat Enterprise Linux 7
curl
Fix deferred
Red Hat Software Collections
httpd24-curl
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | curl-0:7.61.1-18.el8 | Fixed | RHSA-2021:1610 |
| .NET Core 2.1 on Red Hat Enterprise Linux | rh-dotnet21-curl | Not affected | n/a |
| .NET Core 3.1 on Red Hat Enterprise Linux | rh-dotnet31-curl | Not affected | n/a |
| Red Hat Ceph Storage 2 | curl | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | curl | Fix deferred | n/a |
| Red Hat Software Collections | httpd24-curl | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2020-8231 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1868032 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf x_refsource_CONFIRMPatchThird Party Advisory
- https://curl.haxx.se/docs/CVE-2020-8231.html x_refsource_MISCPatchThird Party Advisory
- https://hackerone.com/reports/948876 x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8231
- https://security.gentoo.org/glsa/202012-14 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8231
- https://www.debian.org/security/2021/dsa-4881 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.