RHSA-2021:4511: Moderate: curl security and bug fix update
The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.Security Fix(es): curl: Leak of authentication credentials in URL via automatic Referer (CVE-2021-22876) curl: TELNET stack contents disclosure (CVE-2021-22898) curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure (CVE-2021-22925) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:4511?
The severity of RHSA-2021:4511 is considered critical due to the potential leak of authentication credentials.
How do I fix RHSA-2021:4511?
To fix RHSA-2021:4511, update to the curl package version 7.61.1-22.el8 or later.
Which packages are affected by RHSA-2021:4511?
Affected packages include curl, libcurl, and their respective debuginfo and debugsource versions prior to 7.61.1-22.el8.
What vulnerability does RHSA-2021:4511 address?
RHSA-2021:4511 addresses a vulnerability identified as CVE-2021-22876, which involves the leak of authentication credentials.
Is my system vulnerable if I use curl version lower than 7.61.1-22.el8?
Yes, systems using curl versions lower than 7.61.1-22.el8 are vulnerable to the issues described in RHSA-2021:4511.