Уязвимость утечки информации в curl, приводящая к раскрытию части пароля через сеть и DNS серверы
Описание
В curl обнаружена уязвимость, связанная с утечкой информации. Эта уязвимость приводит к тому, что часть пароля может быть передана через сеть и на DNS серверы.
Затронутые версии ПО
- curl версии с 7.62.0 по 7.70.0
Тип уязвимости
Утечка информации
Ссылки
- Third Party Advisory
- PatchThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одновременно
Одно из
EPSS
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure ...
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
EPSS
7.5 High
CVSS3
5 Medium
CVSS2