[GLSA-202105-36] cURL: Multiple vulnerabilities

Severity High
Affected Packages 1
Unaffected Packages 1
CVEs 4

Multiple vulnerabilities have been found in cURL, the worst of which could result in the arbitrary execution of code.

Background
A command line tool and library for transferring data with URLs.

Description
Multiple vulnerabilities have been discovered in cURL. Please review the
CVE identifiers referenced below for details.

Impact
Please review the referenced CVE identifiers for details.

Workaround
There is no known workaround at this time.

Resolution
All cURL users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/curl-7.77.0"

Package Affected Version
pkg:ebuild/net-misc/curl?distro=gentoo < 7.77.0
Package Unaffected Version
pkg:ebuild/net-misc/curl?distro=gentoo >= 7.77.0
Source # ID Name URL
CVE CVE-2021-22876 CVE-2021-22876 https://nvd.nist.gov/vuln/detail/CVE-2021-22876
CVE CVE-2021-22890 CVE-2021-22890 https://nvd.nist.gov/vuln/detail/CVE-2021-22890
CVE CVE-2021-22898 CVE-2021-22898 https://nvd.nist.gov/vuln/detail/CVE-2021-22898
CVE CVE-2021-22901 CVE-2021-22901 https://nvd.nist.gov/vuln/detail/CVE-2021-22901
Bugzilla 779535 Bugzilla #779535 https://bugs.gentoo.org/show_bug.cgi?id=779535
Bugzilla 792192 Bugzilla #792192 https://bugs.gentoo.org/show_bug.cgi?id=792192
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/net-misc/curl?distro=gentoo net-misc curl < 7.77.0 gentoo
Unaffected pkg:ebuild/net-misc/curl?distro=gentoo net-misc curl >= 7.77.0 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...