漏洞信息详情
Haxx libcurl 信息泄露漏洞
漏洞简介
HAXX Haxx libcurl是瑞典HAXX公司的一个免费、开源的客户端URL传输库。该库支持FTP、FTPS、TFTP、HTTP等。
libcurl 存在信息泄露漏洞,攻击者可利用该漏洞绕过对数据的访问限制,以获取敏感信息。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
http://www.debian.org/security/2021/dsa-4881
参考网址
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/2ZC5BMIOKLBQJSFCHEDN2G2C2SH274BP/
来源:MISC
链接:https://hackerone.com/reports/1101882
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/05/msg00019.html
来源:MISC
链接:https://curl.se/docs/CVE-2021-22876.html
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/ITVWPVGLFISU5BJC2BXBRYSDXTXE2YGC/
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20210521-0007/
来源:GENTOO
链接:https://security.gentoo.org/glsa/202105-36
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/KQUIOYX2KUU6FIUZVB5WWZ6JHSSYSQWJ/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-was-identified-and-remediated-in-the-ibm-maas360-cloud-extender-v2-103-000-051-and-modules/
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2021-22876
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163193/Red-Hat-Security-Advisory-2021-2471-01.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021052711
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164886/Red-Hat-Security-Advisory-2021-4511-03.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021111131
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1129
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1841
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021071312
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3905
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.4019
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3748
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1670
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1114
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-curl-affect-powersc-cve-2021-22876-and-cve-2021-22890/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162116/Ubuntu-Security-Notice-USN-4903-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2168
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1178
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021062142
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162037/Ubuntu-Security-Notice-USN-4898-1.html
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-22876
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/libcurl-information-disclosure-via-Auto-Referer-Header-Credentials-34977
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162817/Gentoo-Linux-Security-Advisory-202105-36.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/165096/Red-Hat-Security-Advisory-2021-4845-05.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3935
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1118
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1859
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/165002/Red-Hat-Security-Advisory-2021-4032-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/165099/Red-Hat-Security-Advisory-2021-4848-07.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1461
受影响实体
暂无
补丁
- HAXX libcurl 信息泄露漏洞的修复措施<!--2021-3-31-->
还没有评论,来说两句吧...