Логотип exploitDog
bind:"CVE-2021-22925"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-22925"

Количество 15

Количество 15

ubuntu логотип

CVE-2021-22925

почти 4 года назад

curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2021-22925

почти 4 года назад

curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2021-22925

почти 4 года назад

curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-22925

почти 4 года назад

curl supports the `-t` command line option, known as `CURLOPT_TELNETOP ...

CVSS3: 5.3
EPSS: Низкий
rocky логотип

RLSA-2021:4511

больше 3 лет назад

Moderate: curl security and bug fix update

EPSS: Низкий
github логотип

GHSA-rjqf-6h27-xqfp

около 3 лет назад

curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2022-00343

почти 4 года назад

Уязвимость служебной программы командной строки cURL, связанная с использованием неинициализированного ресурса, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 5.3
EPSS: Низкий
oracle-oval логотип

ELSA-2021-4511

больше 3 лет назад

ELSA-2021-4511: curl security and bug fix update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2439-1

почти 4 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1088-1

почти 4 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2462-1

почти 4 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2440-1

почти 4 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2439-1

почти 4 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2425-1

почти 4 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:14768-1

почти 4 года назад

Security update for curl

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-22925

curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2021-22925

curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.

CVSS3: 3.1
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-22925

curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-22925

curl supports the `-t` command line option, known as `CURLOPT_TELNETOP ...

CVSS3: 5.3
0%
Низкий
почти 4 года назад
rocky логотип
RLSA-2021:4511

Moderate: curl security and bug fix update

0%
Низкий
больше 3 лет назад
github логотип
GHSA-rjqf-6h27-xqfp

curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2022-00343

Уязвимость служебной программы командной строки cURL, связанная с использованием неинициализированного ресурса, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 5.3
0%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2021-4511

ELSA-2021-4511: curl security and bug fix update (MODERATE)

больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:2439-1

Security update for curl

почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1088-1

Security update for curl

почти 4 года назад
suse-cvrf логотип
SUSE-SU-2021:2462-1

Security update for curl

почти 4 года назад
suse-cvrf логотип
SUSE-SU-2021:2440-1

Security update for curl

почти 4 года назад
suse-cvrf логотип
SUSE-SU-2021:2439-1

Security update for curl

почти 4 года назад
suse-cvrf логотип
SUSE-SU-2021:2425-1

Security update for curl

почти 4 года назад
suse-cvrf логотип
SUSE-SU-2021:14768-1

Security update for curl

почти 4 года назад

Уязвимостей на страницу