Log

ASA-202106-10 created at 01 Jun 2021 16:39:16
ASA-202106-11 created at 01 Jun 2021 16:39:16
ASA-202106-9 edited at 01 Jun 2021 16:38:53
Workaround
+ The issue can be mitigated by avoiding to use the -t command line option and CURLOPT_TELNETOPTIONS.
Impact
+ curl could disclose potentially sensitive memory information to a remote server over Telnet when an uncommon option is used.
ASA-202106-9 created at 01 Jun 2021 16:38:42
ASA-202106-8 edited at 01 Jun 2021 16:38:32
Workaround
+ The issue can be mitigated by avoiding to use the -t command line option and CURLOPT_TELNETOPTIONS.
Impact
+ curl could disclose potentially sensitive memory information to a remote server over Telnet when an uncommon option is used.
ASA-202106-8 created at 01 Jun 2021 16:38:01
ASA-202106-7 edited at 01 Jun 2021 16:37:51
Workaround
+ - CVE-2021-22898 can be mitigated by avoiding to use the -t command line option and CURLOPT_TELNETOPTIONS.
+ - No known workaround exists for CVE-2021-22901.
Impact
+ curl could disclose potentially sensitive memory information to a remote server over Telnet when an uncommon option is used. Additionally, a remote attacker could cause arbitrary code execution through a crafted TLS handshake.
ASA-202106-7 created at 01 Jun 2021 16:37:40
ASA-202106-6 edited at 01 Jun 2021 16:37:33
Workaround
+ - CVE-2021-22898 can be mitigated by avoiding to use the -t command line option and CURLOPT_TELNETOPTIONS.
+ - No known workaround exists for CVE-2021-22901.
Impact
+ curl could disclose potentially sensitive memory information to a remote server over Telnet when an uncommon option is used. Additionally, a remote attacker could cause arbitrary code execution through a crafted TLS handshake.
ASA-202106-6 created at 01 Jun 2021 16:37:23