libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Haxx
Subscribe
|
Libcurl
Subscribe
|
|
Netapp
Subscribe
|
|
|
Oracle
Subscribe
|
|
|
Redhat
Subscribe
|
|
|
Siemens
Subscribe
|
Logo\! Cmr2020
Subscribe
Logo\! Cmr2020 Firmware
Subscribe
Logo\! Cmr2040
Subscribe
Logo\! Cmr2040 Firmware
Subscribe
Ruggedcomrm 1224 Lte
Subscribe
Ruggedcomrm 1224 Lte Firmware
Subscribe
Scalance M804pb
Subscribe
Scalance M804pb Firmware
Subscribe
Scalance M812-1
Subscribe
Scalance M812-1 Firmware
Subscribe
Scalance M816-1
Subscribe
Scalance M816-1 Firmware
Subscribe
Scalance M826-2
Subscribe
Scalance M826-2 Firmware
Subscribe
Scalance M874-2
Subscribe
Scalance M874-2 Firmware
Subscribe
Scalance M874-3
Subscribe
Scalance M874-3 Firmware
Subscribe
Scalance M876-3
Subscribe
Scalance M876-3 Firmware
Subscribe
Scalance M876-4
Subscribe
Scalance M876-4 Firmware
Subscribe
Scalance Mum856-1
Subscribe
Scalance Mum856-1 Firmware
Subscribe
Scalance S615
Subscribe
Scalance S615 Firmware
Subscribe
Simatic Cp 1543-1
Subscribe
Simatic Cp 1543-1 Firmware
Subscribe
Simatic Cp 1545-1
Subscribe
Simatic Cp 1545-1 Firmware
Subscribe
Simatic Rtu3010c
Subscribe
Simatic Rtu3010c Firmware
Subscribe
Simatic Rtu3030c
Subscribe
Simatic Rtu3030c Firmware
Subscribe
Simatic Rtu3031c
Subscribe
Simatic Rtu3031c Firmware
Subscribe
Simatic Rtu 3041c
Subscribe
Simatic Rtu 3041c Firmware
Subscribe
Sinec Infrastructure Network Services
Subscribe
Sinema Remote Connect
Subscribe
Sinema Remote Connect Server
Subscribe
Siplus Net Cp 1543-1
Subscribe
Siplus Net Cp 1543-1 Firmware
Subscribe
|
|
Splunk
Subscribe
|
Universal Forwarder
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2734-1 | curl security update |
Debian DLA |
DLA-3085-1 | curl security update |
Debian DSA |
DSA-5197-1 | curl security update |
EUVD |
EUVD-2021-10053 | libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate. |
Ubuntu USN |
USN-5021-1 | curl vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 09 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-06-09T15:02:19.721Z
Reserved: 2021-01-06T00:00:00.000Z
Link: CVE-2021-22924
Updated: 2024-08-03T18:58:25.955Z
Status : Modified
Published: 2021-08-05T21:15:11.380
Modified: 2025-06-09T15:15:24.403
Link: CVE-2021-22924
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN