QID 198316

Date Published: 2021-04-06

QID 198316: Ubuntu Security Notification for Curl Vulnerabilities (USN-4898-1)

It was discovered that curl did not strip off user credentials from referrer header fields.

It was discovered that curl incorrectly handled session tickets when using an HTTPS proxy.

A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2021-22876)

A remote attacker in control of an HTTPS proxy could use this issue to bypass certificate checks and intercept communications. This issue only affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-22890)

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Ubuntu advisory USN-4898-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198316

    Software Advisories
    Advisory ID Software Component Link
    USN-4898-1 16.04 (Xenial) on src curl URL Logo launchpad.net/ubuntu/+source/curl/7.47.0-1ubuntu2.19
    USN-4898-1 16.04 (Xenial) on src libcurl3 URL Logo launchpad.net/ubuntu/+source/curl/7.47.0-1ubuntu2.19
    USN-4898-1 16.04 (Xenial) on src libcurl3-gnutls URL Logo launchpad.net/ubuntu/+source/curl/7.47.0-1ubuntu2.19
    USN-4898-1 16.04 (Xenial) on src libcurl3-nss URL Logo launchpad.net/ubuntu/+source/curl/7.47.0-1ubuntu2.19
    USN-4898-1 18.04 (bionic) on src curl URL Logo launchpad.net/ubuntu/+source/curl/7.58.0-2ubuntu3.13
    USN-4898-1 18.04 (bionic) on src libcurl3-gnutls URL Logo launchpad.net/ubuntu/+source/curl/7.58.0-2ubuntu3.13
    USN-4898-1 18.04 (bionic) on src libcurl3-nss URL Logo launchpad.net/ubuntu/+source/curl/7.58.0-2ubuntu3.13
    USN-4898-1 18.04 (bionic) on src libcurl4 URL Logo launchpad.net/ubuntu/+source/curl/7.58.0-2ubuntu3.13
    USN-4898-1 20.04 (focal) on src curl URL Logo launchpad.net/ubuntu/+source/curl/7.68.0-1ubuntu2.5
    USN-4898-1 20.04 (focal) on src libcurl3-gnutls URL Logo launchpad.net/ubuntu/+source/curl/7.68.0-1ubuntu2.5
    USN-4898-1 20.04 (focal) on src libcurl3-nss URL Logo launchpad.net/ubuntu/+source/curl/7.68.0-1ubuntu2.5
    USN-4898-1 20.04 (focal) on src libcurl4 URL Logo launchpad.net/ubuntu/+source/curl/7.68.0-1ubuntu2.5
    USN-4898-1 20.10 (groovy) on src curl URL Logo launchpad.net/ubuntu/+source/curl/7.68.0-1ubuntu4.3
    USN-4898-1 20.10 (groovy) on src libcurl3-gnutls URL Logo launchpad.net/ubuntu/+source/curl/7.68.0-1ubuntu4.3
    USN-4898-1 20.10 (groovy) on src libcurl3-nss URL Logo launchpad.net/ubuntu/+source/curl/7.68.0-1ubuntu4.3
    USN-4898-1 20.10 (groovy) on src libcurl4 URL Logo launchpad.net/ubuntu/+source/curl/7.68.0-1ubuntu4.3