libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths case insensitively,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"vendor_product": "debian:debian_linux",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "9.0"
},
{
"last_affected": "10.0"
},
{
"last_affected": "11.0"
}
]
},
{
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*"
],
"vendor_product": "fedoraproject:fedora",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "33"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:peoplesoft_enterprise_peopletools",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8.57"
},
{
"last_affected": "8.58"
},
{
"last_affected": "8.59"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:ruggedcomrm_1224_lte_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:ruggedcomrm_1224_lte_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "7.1"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:scalance_m804pb_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:scalance_m804pb_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "7.1"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:scalance_m812-1_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:scalance_m812-1_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "7.1"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:scalance_m816-1_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:scalance_m816-1_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "7.1"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:scalance_m826-2_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:scalance_m826-2_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "7.1"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:scalance_m874-2_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:scalance_m874-2_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "7.1"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:scalance_m874-3_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:scalance_m874-3_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "7.1"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:scalance_m876-3_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:scalance_m876-3_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "7.1"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:scalance_m876-4_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:scalance_m876-4_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "7.1"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:scalance_mum856-1_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:scalance_mum856-1_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "7.1"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:scalance_s615_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:scalance_s615_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "7.1"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:simatic_cp_1543-1_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:simatic_cp_1543-1_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "3.0.22"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:simatic_cp_1545-1_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:simatic_cp_1545-1_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "1.1"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:simatic_rtu3010c_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:simatic_rtu3010c_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "5.0.14"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:simatic_rtu3030c_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:simatic_rtu3030c_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "5.0.14"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:simatic_rtu3031c_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:simatic_rtu3031c_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "5.0.14"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:simatic_rtu_3041c_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:simatic_rtu_3041c_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "5.0.14"
}
]
},
{
"cpes": [
"cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:sinec_infrastructure_network_services",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "1.0.1.1"
}
]
},
{
"cpes": [
"cpe:2.3:a:siemens:sinema_remote_connect:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:sinema_remote_connect",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "3.1"
}
]
},
{
"cpes": [
"cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:sinema_remote_connect_server",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "3.1"
}
]
},
{
"cpes": [
"cpe:2.3:o:siemens:siplus_net_cp_1543-1_firmware:*:*:*:*:*:*:*:*"
],
"vendor_product": "siemens:siplus_net_cp_1543-1_firmware",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "3.0.22"
}
]
},
{
"cpes": [
"cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*",
"cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*"
],
"vendor_product": "splunk:universal_forwarder",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "8.2.0"
},
{
"fixed": "8.2.12"
},
{
"introduced": "9.0.0"
},
{
"fixed": "9.0.6"
},
{
"last_affected": "9.1.0"
}
]
}
]
}{
"cpe": "cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "5.7.0"
},
{
"last_affected": "5.7.36"
},
{
"introduced": "8.0.0"
},
{
"last_affected": "8.0.26"
}
]
}