• 公告ID (KylinSec-SA-2022-1134)

摘要:

libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take issuercert into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn t include the issuer cert which a transfer can setto qualify how to verify the server certificate.

安全等级: Low

公告ID: KylinSec-SA-2022-1134

发布日期: 2022年9月29日

关联CVE: CVE-2021-22924  

  • 详细介绍

1. 漏洞描述

   

libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take issuercert into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn t include the issuer cert which a transfer can setto qualify how to verify the server certificate.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2021-22924 KY3.4-4A mysql Unaffected
CVE-2021-22924 KY3.4-5 mysql Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2022-1133 下一篇:KylinSec-SA-2022-1135