Логотип exploitDog
bind:"GHSA-7w8r-q58w-5wcr" OR bind:"CVE-2021-22898"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-7w8r-q58w-5wcr" OR bind:"CVE-2021-22898"

Количество 16

Количество 16

github логотип

GHSA-7w8r-q58w-5wcr

около 3 лет назад

curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2021-22898

около 4 лет назад

curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2021-22898

около 4 лет назад

curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2021-22898

около 4 лет назад

curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.

CVSS3: 3.1
EPSS: Низкий
msrc логотип

CVE-2021-22898

почти 4 года назад

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2021-22898

около 4 лет назад

curl 7.7 through 7.76.1 suffers from an information disclosure when th ...

CVSS3: 3.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1762-1

почти 4 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0808-1

около 4 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1763-1

около 4 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1762-1

около 4 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:14760-1

почти 4 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:14735-1

около 4 лет назад

Security update for curl

EPSS: Низкий
fstec логотип

BDU:2021-03580

около 4 лет назад

Уязвимость функции sscanf() библиотеки libcurl программного средства для взаимодействия с серверами CURL, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1809-1

около 4 лет назад

Security update for curl

EPSS: Низкий
oracle-oval логотип

ELSA-2021-4511

больше 3 лет назад

ELSA-2021-4511: curl security and bug fix update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1786-1

около 4 лет назад

Security update for curl

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-7w8r-q58w-5wcr

curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.

CVSS3: 3.1
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2021-22898

curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.

CVSS3: 3.1
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-22898

curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.

CVSS3: 3.1
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-22898

curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.

CVSS3: 3.1
0%
Низкий
около 4 лет назад
msrc логотип
CVSS3: 3.1
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-22898

curl 7.7 through 7.76.1 suffers from an information disclosure when th ...

CVSS3: 3.1
0%
Низкий
около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1762-1

Security update for curl

0%
Низкий
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:0808-1

Security update for curl

0%
Низкий
около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:1763-1

Security update for curl

0%
Низкий
около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:1762-1

Security update for curl

0%
Низкий
около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:14760-1

Security update for curl

0%
Низкий
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2021:14735-1

Security update for curl

0%
Низкий
около 4 лет назад
fstec логотип
BDU:2021-03580

Уязвимость функции sscanf() библиотеки libcurl программного средства для взаимодействия с серверами CURL, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.1
0%
Низкий
около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:1809-1

Security update for curl

около 4 лет назад
oracle-oval логотип
ELSA-2021-4511

ELSA-2021-4511: curl security and bug fix update (MODERATE)

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:1786-1

Security update for curl

около 4 лет назад

Уязвимостей на страницу