← Search the atlas
SUSE-SU-2021:1809-1
Not scored
Security update for curl
This update for curl fixes the following issues:
- CVE-2021-22876: Fixed an issue where the automatic referer was leaking credentials (bsc#1183933).
- CVE-2021-22898: Fixed curl TELNET stack contents disclosure (bsc#1186114).
- Fix for SFTP uploads when it results in empty uploaded files (bsc#1177976).
- Allow partial chain verification (jsc#SLE-17956).
Exploit probability
Not scored
Published
May 31, 2021
Required by
Not available
Last source change
May 2, 2025
02 / AFFECTED SOFTWARE
Affected packages
SUSE:Manager Retail Branch Server 4.0
curl
SUSE:Enterprise Storage 6
curl
SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS
curl
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS
curl
SUSE:Linux Enterprise High Performance Computing 15-ESPOS
curl
SUSE:Linux Enterprise High Performance Computing 15-LTSS
curl
SUSE:Linux Enterprise Server 15 SP1-BCL
curl
SUSE:Linux Enterprise Server 15 SP1-LTSS
curl
SUSE:Linux Enterprise Server 15-LTSS
curl
SUSE:Linux Enterprise Server for SAP Applications 15
curl
SUSE:Linux Enterprise Server for SAP Applications 15 SP1
curl
SUSE:Manager Proxy 4.0
curl
SUSE:Manager Server 4.0
curl
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2021:1809-1
This update for curl fixes the following issues:
- CVE-2021-22876: Fixed an issue where the automatic referer was leaking credentials (bsc#1183933).
- CVE-2021-22898: Fixed curl TELNET stack contents disclosure (bsc#1186114).
- Fix for SFTP uploads when it results in empty uploaded files (bsc#1177976).
- Allow partial chain verification (jsc#SLE-17956).
View original source ↗
05 / REFERENCES
Further evidence