Log

ASA-202106-6 created at 01 Jun 2021 16:37:23
ASA-202106-5 edited at 01 Jun 2021 16:37:16
Workaround
+ - CVE-2021-22898 can be mitigated by avoiding to use the -t command line option and CURLOPT_TELNETOPTIONS.
+ - No known workaround exists for CVE-2021-22901.
Impact
+ curl could disclose potentially sensitive memory information to a remote server over Telnet when an uncommon option is used. Additionally, a remote attacker could cause arbitrary code execution through a crafted TLS handshake.
ASA-202106-5 created at 01 Jun 2021 16:36:51
ASA-202106-4 edited at 01 Jun 2021 16:36:20
Workaround
+ - CVE-2021-22898 can be mitigated by avoiding to use the -t command line option and CURLOPT_TELNETOPTIONS.
+ - No known workaround exists for CVE-2021-22901.
Impact
+ curl could disclose potentially sensitive memory information to a remote server over Telnet when an uncommon option is used. Additionally, a remote attacker could cause arbitrary code execution through a crafted TLS handshake.
ASA-202106-4 created at 01 Jun 2021 16:29:41
ASA-202106-3 edited at 01 Jun 2021 16:28:39
Impact
+ A remote attacker could spoof the user interface, record audio and video without an additional prompt, or execute arbitrary code through crafted web pages. A local attacker could learn the title of a website visited during private browsing mode.
ASA-202106-3 created at 01 Jun 2021 16:26:00
ASA-202106-2 edited at 01 Jun 2021 16:25:51
Impact
+ A remote attacker could spoof content, disclose sensitive information, or execute arbitrary code through crafted web pages.
ASA-202106-2 created at 01 Jun 2021 16:24:42
ASA-202106-1 edited at 01 Jun 2021 16:24:22
Impact
+ A remote attacker could spoof content, disclose sensitive information, or execute arbitrary code through crafted web pages.