CVE-2021-22945
Published on: 09/23/2021 12:00:00 AM UTC
Last Modified on: 12/22/2022 08:21:00 PM UTC
Certain versions of Macos from Apple contain the following vulnerability:
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.
- CVE-2021-22945 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.1 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | HIGH |
CVSS2 Score: 5.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
HackerOne | hackerone.com text/html |
![]() |
[SECURITY] Fedora 33 Update: curl-7.71.1-11.fc33 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
Full Disclosure: APPLE-SA-2022-03-14-4 macOS Monterey 12.3 | seclists.org text/html |
![]() |
[SECURITY] Fedora 35 Update: curl-7.79.1-1.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
curl: Multiple Vulnerabilities (GLSA 202212-01) — Gentoo security | security.gentoo.org text/html |
![]() |
September 2021 cURL/libcURL Vulnerabilities in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
Oracle Critical Patch Update Advisory - October 2021 | www.oracle.com text/html |
![]() |
cert-portal.siemens.com application/pdf |
![]() | |
Debian -- Security Information -- DSA-5197-1 curl | www.debian.org Depreciated Link text/html |
![]() |
About the security content of macOS Monterey 12.3 - Apple Support (PH) | support.apple.com text/html |
![]() |
Related QID Numbers
- 180909 Debian Security Update for curl (DSA 5197-1)
- 198501 Ubuntu Security Notification for curl Vulnerabilities (USN-5079-1)
- 281920 Fedora Security Update for curl (FEDORA-2021-c5584b92d4)
- 281955 Fedora Security Update for curl (FEDORA-2021-fc96a3a749)
- 296065 Oracle Solaris 11.4 Support Repository Update (SRU) 39.107.1 Missing (CPUOCT2021)
- 353082 Amazon Linux Security Advisory for curl : ALAS2-2021-1724
- 376485 Apple MacOS Monterey 12.3 Not Installed (HT213183)
- 376968 NetApp Clustered Data Open Network Technology for Appliance Products (ONTAP) Disclosure of Sensitive Information Vulnerability (NTAP-20211029-0003)
- 500137 Alpine Linux Security Update for curl
- 690014 Free Berkeley Software Distribution (FreeBSD) Security Update for curl (c9221ec9-17a2-11ec-b335-d4c9ef517024)
- 710693 Gentoo Linux curl Multiple Vulnerabilities (GLSA 202212-01)
- 730371 McAfee Web Gateway Multiple Vulnerabilities (WP-3335,WP-4131,WP-4159,WP-4237,WP-4259,WP-4329,WP-4348,WP-4355,WP-4376,WP-4407,WP-4421)
- 900339 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (5940)
- 901395 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (6368-1)
- 904921 Common Base Linux Mariner (CBL-Mariner) Security Update for cmake (12310)
- 905106 Common Base Linux Mariner (CBL-Mariner) Security Update for cmake (12466)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Apple | Macos | All | All | All | All |
Operating System | Debian | Debian Linux | 11.0 | All | All | All |
Operating System | Fedoraproject | Fedora | 33 | All | All | All |
Operating System | Fedoraproject | Fedora | 35 | All | All | All |
Application | Haxx | Libcurl | All | All | All | All |
Application | Netapp | Cloud Backup | - | All | All | All |
Application | Netapp | Clustered Data Ontap | - | All | All | All |
Hardware
| Netapp | H300e | - | All | All | All |
Operating System | Netapp | H300e Firmware | - | All | All | All |
Hardware
| Netapp | H300s | - | All | All | All |
Operating System | Netapp | H300s Firmware | - | All | All | All |
Hardware
| Netapp | H410s | - | All | All | All |
Operating System | Netapp | H410s Firmware | - | All | All | All |
Hardware
| Netapp | H500e | - | All | All | All |
Operating System | Netapp | H500e Firmware | - | All | All | All |
Hardware
| Netapp | H500s | - | All | All | All |
Operating System | Netapp | H500s Firmware | - | All | All | All |
Hardware
| Netapp | H700e | - | All | All | All |
Operating System | Netapp | H700e Firmware | - | All | All | All |
Hardware
| Netapp | H700s | - | All | All | All |
Operating System | Netapp | H700s Firmware | - | All | All | All |
Hardware
| Netapp | Solidfire Baseboard Management Controller | - | All | All | All |
Operating System | Netapp | Solidfire Baseboard Management Controller Firmware | - | All | All | All |
Application | Oracle | Mysql Server | All | All | All | All |
Application | Oracle | Mysql Server | All | All | All | All |
Application | Siemens | Sinec Ins | All | All | All | All |
- cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*:
- cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h300e:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h500e:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h700e:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:solidfire_baseboard_management_controller:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:solidfire_baseboard_management_controller_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinec_ins:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-22945 (curl.se/docs/CVE-2021-…) is a stupid double-free in relatively new MQTT send code. Not a lot to say. | 2021-09-15 06:28:21 |
![]() |
SIOSセキュリティブログを更新しました。 curlの複数の脆弱性情報(Medium: CVE-2021-22945, CVE-2021-22946, CVE-2021-22947 ) #sios_tech #security… twitter.com/i/web/status/1… | 2021-09-15 18:02:00 |
![]() |
[email protected] changed net/curl: net/curl: security update to 7.79.0 Includes fixes for CVE-2021-22945: UAF and double-free… twitter.com/i/web/status/1… | 2021-09-17 21:55:25 |
![]() |
OPENBSD_6_9 [email protected] changed net/curl: net/curl: security update to 7.79.0 Includes fixes for CVE-2021-22945: UAF and… twitter.com/i/web/status/1… | 2021-09-17 21:55:25 |
![]() |
OPENBSD_6_9 [email protected] changed net/curl: net/curl: security update to 7.79.0 Includes fixes for CVE-2021-22945: UAF and… twitter.com/i/web/status/1… | 2021-09-17 21:55:25 |
![]() |
CVE-2021-22945 : When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erro… twitter.com/i/web/status/1… | 2021-09-23 13:05:56 |
![]() |
MS-ISAC CYBERSECURITY ADVISORY - Multiple Vulnerabilities in Apple Products Could Allow for Arbitrary Code Execution - PATCH: NOW | 2022-03-15 13:18:46 |