Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2021-22898: curl: TELNET stack contents disclosure (1/2) | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Robert Frohl <rfrohl> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P3 - Medium | CC: | abergmann, hhetter, meissner, pmonrealgonzalez |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/284454/ | ||
Whiteboard: | CVSSv3.1:SUSE:CVE-2021-22898:5.3:(AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) | ||
Found By: | --- | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Comment 12
Marcus Meissner
2021-05-26 07:44:02 UTC
Curl update to 7.77.0, submitted here: https://build.opensuse.org/request/show/895500 SUSE-SU-2021:1763-1: An update that fixes one vulnerability, contains one feature is now available. Category: security (moderate) Bug References: 1186114 CVE References: CVE-2021-22898 JIRA References: SLE-17954 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): curl-7.60.0-11.18.1 SUSE Linux Enterprise Server 12-SP5 (src): curl-7.60.0-11.18.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2021:14735-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1186114 CVE References: CVE-2021-22898 JIRA References: Sources used: SUSE Linux Enterprise Server 11-SECURITY (src): curl-openssl1-7.37.0-70.63.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2021:1762-1: An update that fixes one vulnerability, contains one feature is now available. Category: security (moderate) Bug References: 1186114 CVE References: CVE-2021-22898 JIRA References: SLE-17956 Sources used: SUSE MicroOS 5.0 (src): curl-7.66.0-4.17.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): curl-7.66.0-4.17.1 SUSE Linux Enterprise Module for Basesystem 15-SP2 (src): curl-7.66.0-4.17.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2021:1786-1: An update that solves 6 vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 1175109,1177976,1179398,1179399,1179593,1183933,1186114 CVE References: CVE-2020-8231,CVE-2020-8284,CVE-2020-8285,CVE-2020-8286,CVE-2021-22876,CVE-2021-22898 JIRA References: Sources used: SUSE OpenStack Cloud Crowbar 9 (src): curl-7.60.0-4.20.1 SUSE OpenStack Cloud 9 (src): curl-7.60.0-4.20.1 SUSE Linux Enterprise Server for SAP 12-SP4 (src): curl-7.60.0-4.20.1 SUSE Linux Enterprise Server 12-SP4-LTSS (src): curl-7.60.0-4.20.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. openSUSE-SU-2021:0808-1: An update that fixes one vulnerability, contains one feature is now available. Category: security (moderate) Bug References: 1186114 CVE References: CVE-2021-22898 JIRA References: SLE-17956 Sources used: openSUSE Leap 15.2 (src): curl-7.66.0-lp152.3.18.1, curl-mini-7.66.0-lp152.3.18.1 SUSE-SU-2021:1809-1: An update that solves two vulnerabilities, contains one feature and has one errata is now available. Category: security (moderate) Bug References: 1177976,1183933,1186114 CVE References: CVE-2021-22876,CVE-2021-22898 JIRA References: SLE-13843 Sources used: SUSE Manager Server 4.0 (src): curl-7.60.0-3.42.1 SUSE Manager Retail Branch Server 4.0 (src): curl-7.60.0-3.42.1 SUSE Manager Proxy 4.0 (src): curl-7.60.0-3.42.1 SUSE Linux Enterprise Server for SAP 15-SP1 (src): curl-7.60.0-3.42.1 SUSE Linux Enterprise Server for SAP 15 (src): curl-7.60.0-3.42.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): curl-7.60.0-3.42.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): curl-7.60.0-3.42.1 SUSE Linux Enterprise Server 15-LTSS (src): curl-7.60.0-3.42.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): curl-7.60.0-3.42.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): curl-7.60.0-3.42.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): curl-7.60.0-3.42.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): curl-7.60.0-3.42.1 SUSE Enterprise Storage 6 (src): curl-7.60.0-3.42.1 SUSE CaaS Platform 4.0 (src): curl-7.60.0-3.42.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2021:14760-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1186114 CVE References: CVE-2021-22898 JIRA References: Sources used: SUSE Linux Enterprise Server 11-SP4-LTSS (src): curl-7.37.0-70.66.1 SUSE Linux Enterprise Server 11-SECURITY (src): curl-openssl1-7.37.0-70.66.1 SUSE Linux Enterprise Point of Sale 11-SP3 (src): curl-7.37.0-70.66.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): curl-7.37.0-70.66.1 SUSE Linux Enterprise Debuginfo 11-SP3 (src): curl-7.37.0-70.66.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. openSUSE-SU-2021:1762-1: An update that fixes one vulnerability, contains one feature is now available. Category: security (moderate) Bug References: 1186114 CVE References: CVE-2021-22898 JIRA References: SLE-17956 Sources used: openSUSE Leap 15.3 (src): curl-7.66.0-4.17.1, curl-mini-7.66.0-4.17.1 done |