Chapter 3. Security Fixes

This update includes the following security fixes:

IDImpactSummary

CVE-2020-8284

Moderate

curl: FTP PASV command response can cause curl to connect to arbitrary host [jbcs-httpd-2.4]

CVE-2020-8286

Moderate

curl: inferior OCSP verification [jbcs-httpd-2.4]

CVE-2020-8169

Moderate

curl: libcurl: partial password leak over DNS on HTTP redirect [jbcs-httpd-2.4]

CVE-2021-22876

Moderate

curl: Leak of authentication credentials in URL via automatic Referer [jbcs-httpd-2.4]

CVE-2020-8285

Moderate

curl:malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used [jbcs-httpd-2.4]

CVE-2021-22890

Low

curl: TLS 1.3 session ticket mix-up with HTTPS proxy host [jbcs-httpd-2.4]

CVE-2021-22901

Important

curl: Use-after-free in TLS session handling when using OpenSSL TLS backend [jbcs-httpd-2.4]

CVE-2021-31618

Important

httpd: NULL pointer dereference on specially crafted HTTP/2 request [jbcs-httpd-2.4]