Sploitus

CVE-2021-22925

No indexed exploits for CVE-2021-22925 yet

curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.

Haxx Curl
< 7.78.0
CVSS 3.1
5.3 MEDIUM
EPSS
4.9% (91th percentile)
Weakness
CWE-200, CWE-908
NVD status
Modified
Published
2021-08-05
CVE-2021-22925 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2021-22925 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2021-22925 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.