Lack of data validation In curl
Description
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.13 | 7.79.1-r2 | ||
alpine v3.14 | 7.79.1-r2 | ||
alpine v3.16 | 7.83.1-r2 | ||
alpine v3.17 | 7.84.0-r0 | ||
alpine v3.21 | 7.84.0-r0 | ||
alpine v3.22 | 7.84.0-r0 | ||
debian 12 | 7.84.0-1 | ||
debian 13 | 7.84.0-1 | ||
debian 14 | 7.84.0-1 | ||
rpm rhel8 | 0:7.61.1-22.el8_6.4 |
1-10 of 19
10
Aliases
1. 2. 3. 4. 5. 6. 7.