Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8231

Опубликовано: 19 авг. 2020
Источник: redhat
CVSS3: 3.7

Описание

Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.

A flaw was found in libcurl from versions 7.29.0 through 7.71.1. An application that performs multiple requests with libcurl's multi API, and sets the CURLOPT_CONNECT_ONLY option, might experience libcurl using the wrong connection. The highest threat from this vulnerability is to data confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 2.1 on Red Hat Enterprise Linuxrh-dotnet21-curlNot affected
.NET Core 3.1 on Red Hat Enterprise Linuxrh-dotnet31-curlNot affected
Red Hat Ceph Storage 2curlOut of support scope
Red Hat Enterprise Linux 5curlNot affected
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlFix deferred
Red Hat Software Collectionshttpd24-curlFix deferred
Red Hat Enterprise Linux 8curlFixedRHSA-2021:161018.05.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-822
https://bugzilla.redhat.com/show_bug.cgi?id=1868032curl: Expired pointer dereference via multi API with CURLOPT_CONNECT_ONLY option set

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.

CVSS3: 7.5
nvd
около 5 лет назад

Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.

CVSS3: 7.5
msrc
почти 5 лет назад

Due to use of a dangling pointer libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.

CVSS3: 7.5
debian
около 5 лет назад

Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can us ...

suse-cvrf
около 5 лет назад

Security update for curl

3.7 Low

CVSS3