CVE-2021-22898

Related Vulnerabilities: CVE-2021-22898  

A vulnerability was found in curl where a flaw in the option parser for sending NEW_ENV variables libcurl can pass uninitialized data from a stack-based buffer to the server. This issue leads to potentially revealing sensitive internal information to the server using a clear-text network protocol. The highest threat from this vulnerability is to confidentiality.

Description

A vulnerability was found in curl where a flaw in the option parser for sending NEW_ENV variables libcurl can pass uninitialized data from a stack-based buffer to the server. This issue leads to potentially revealing sensitive internal information to the server using a clear-text network protocol. The highest threat from this vulnerability is to confidentiality.

Additional Information

  • Bugzilla 1964887: CVE-2021-22898 curl: TELNET stack contents disclosure
  • CWE-457: Use of Uninitialized Variable
  • FAQ: Frequently asked questions about CVE-2021-22898