QID 198316
Date Published: 2021-04-06
QID 198316: Ubuntu Security Notification for Curl Vulnerabilities (USN-4898-1)
It was discovered that curl did not strip off user credentials from referrer header fields.
It was discovered that curl incorrectly handled session tickets when using an HTTPS proxy.
A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2021-22876)
A remote attacker in control of an HTTPS proxy could use this issue to bypass certificate checks and intercept communications. This issue only affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-22890)
Solution
Refer to Ubuntu advisory USN-4898-1 for affected packages and patching details, or update with your package manager.
Vendor References
- USN-4898-1 -
usn.ubuntu.com/4898-1/
CVEs related to QID 198316
Software Advisories