curl supports the -t command line option, known as CURLOPT_TELNETOPTIONSin libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending NEW_ENV variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.
{
"versions": [
{
"introduced": "7.7"
},
{
"fixed": "7.78.0"
}
]
}{
"versions": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.0.26"
},
{
"introduced": "0"
},
{
"last_affected": "9.1.0"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22925.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.15.7-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.15.7-security_update_2021\\-001"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.15.7-security_update_2021\\-002"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.15.7-security_update_2021\\-003"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.15.7-security_update_2021\\-004"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.2.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.3.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.5"
}
]
},
{
"events": [
{
"introduced": "5.7.0"
},
{
"last_affected": "5.7.35"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.57"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.58"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.59"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.0.1.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.1"
}
]
},
{
"events": [
{
"introduced": "8.2.0"
},
{
"fixed": "8.2.12"
}
]
},
{
"events": [
{
"introduced": "9.0.0"
},
{
"fixed": "9.0.6"
}
]
}
]