<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for curl</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2021:1786-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-05-27T14:45:51Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-05-27T14:45:51Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-05-27T14:45:51Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for curl</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for curl fixes the following issues:
- CVE-2021-22898: TELNET stack contents disclosure (bsc#1186114)
- CVE-2021-22876: The automatic referer leaks credentials (bsc#1183933)
- CVE-2020-8286: Inferior OCSP verification (bsc#1179593)
- CVE-2020-8285: FTP wildcard stack overflow (bsc#1179399)
- CVE-2020-8284: Trusting FTP PASV responses (bsc#1179398)
- CVE-2020-8231: libcurl will pick and use the wrong connection with multiple requests with libcurl's multi API and the 'CURLOPT_CONNECT_ONLY' option (bsc#1175109)
- Fix: SFTP uploads result in empty uploaded files (bsc#1177976)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">Container suse/sles12sp4:latest-2021-1786,Image SLES12-SP4-Azure-BYOS-2021-1786,Image SLES12-SP4-EC2-HVM-BYOS-2021-1786,Image SLES12-SP4-GCE-BYOS-2021-1786,Image SLES12-SP4-SAP-Azure-2021-1786,Image SLES12-SP4-SAP-Azure-BYOS-2021-1786,Image SLES12-SP4-SAP-Azure-LI-BYOS-Production-2021-1786,Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production-2021-1786,Image SLES12-SP4-SAP-EC2-HVM-2021-1786,Image SLES12-SP4-SAP-EC2-HVM-BYOS-2021-1786,Image SLES12-SP4-SAP-GCE-2021-1786,Image SLES12-SP4-SAP-GCE-BYOS-2021-1786,SUSE-2021-1786,SUSE-OpenStack-Cloud-9-2021-1786,SUSE-OpenStack-Cloud-Crowbar-9-2021-1786,SUSE-SLE-SAP-12-SP4-2021-1786,SUSE-SLE-SERVER-12-SP4-LTSS-2021-1786</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211786-1/</URL>
      <Description>Link for SUSE-SU-2021:1786-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2021-May/008879.html</URL>
      <Description>E-Mail link for SUSE-SU-2021:1786-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1175109</URL>
      <Description>SUSE Bug 1175109</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1177976</URL>
      <Description>SUSE Bug 1177976</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179398</URL>
      <Description>SUSE Bug 1179398</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179399</URL>
      <Description>SUSE Bug 1179399</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179593</URL>
      <Description>SUSE Bug 1179593</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1183933</URL>
      <Description>SUSE Bug 1183933</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186114</URL>
      <Description>SUSE Bug 1186114</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-8231/</URL>
      <Description>SUSE CVE CVE-2020-8231 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-8284/</URL>
      <Description>SUSE CVE CVE-2020-8284 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-8285/</URL>
      <Description>SUSE CVE CVE-2020-8285 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-8286/</URL>
      <Description>SUSE CVE CVE-2020-8286 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-22876/</URL>
      <Description>SUSE CVE CVE-2021-22876 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-22898/</URL>
      <Description>SUSE CVE CVE-2021-22898 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Container suse/sles12sp4:latest">
      <Branch Type="Product Name" Name="Container suse/sles12sp4:latest">
        <FullProductName ProductID="Container suse/sles12sp4:latest">Container suse/sles12sp4:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP4-Azure-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP4-Azure-BYOS">
        <FullProductName ProductID="Image SLES12-SP4-Azure-BYOS">Image SLES12-SP4-Azure-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP4-EC2-HVM-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP4-EC2-HVM-BYOS">
        <FullProductName ProductID="Image SLES12-SP4-EC2-HVM-BYOS">Image SLES12-SP4-EC2-HVM-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP4-GCE-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP4-GCE-BYOS">
        <FullProductName ProductID="Image SLES12-SP4-GCE-BYOS">Image SLES12-SP4-GCE-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP4-SAP-Azure">
      <Branch Type="Product Name" Name="Image SLES12-SP4-SAP-Azure">
        <FullProductName ProductID="Image SLES12-SP4-SAP-Azure">Image SLES12-SP4-SAP-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP4-SAP-Azure-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP4-SAP-Azure-BYOS">
        <FullProductName ProductID="Image SLES12-SP4-SAP-Azure-BYOS">Image SLES12-SP4-SAP-Azure-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP4-SAP-Azure-LI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES12-SP4-SAP-Azure-LI-BYOS-Production">
        <FullProductName ProductID="Image SLES12-SP4-SAP-Azure-LI-BYOS-Production">Image SLES12-SP4-SAP-Azure-LI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production">
        <FullProductName ProductID="Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production">Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP4-SAP-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES12-SP4-SAP-EC2-HVM">
        <FullProductName ProductID="Image SLES12-SP4-SAP-EC2-HVM">Image SLES12-SP4-SAP-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP4-SAP-EC2-HVM-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP4-SAP-EC2-HVM-BYOS">
        <FullProductName ProductID="Image SLES12-SP4-SAP-EC2-HVM-BYOS">Image SLES12-SP4-SAP-EC2-HVM-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP4-SAP-GCE">
      <Branch Type="Product Name" Name="Image SLES12-SP4-SAP-GCE">
        <FullProductName ProductID="Image SLES12-SP4-SAP-GCE">Image SLES12-SP4-SAP-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP4-SAP-GCE-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP4-SAP-GCE-BYOS">
        <FullProductName ProductID="Image SLES12-SP4-SAP-GCE-BYOS">Image SLES12-SP4-SAP-GCE-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP4-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS" CPE="cpe:/o:suse:sles-ltss:12:sp4">SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4" CPE="cpe:/o:suse:sles_sap:12:sp4">SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud 9">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud 9">
        <FullProductName ProductID="SUSE OpenStack Cloud 9" CPE="cpe:/o:suse:suse-openstack-cloud:9">SUSE OpenStack Cloud 9</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud Crowbar 9">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud Crowbar 9">
        <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9" CPE="cpe:/o:suse:suse-openstack-cloud-crowbar:9">SUSE OpenStack Cloud Crowbar 9</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libcurl4-7.60.0-4.20.1">
      <FullProductName ProductID="libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="curl-7.60.0-4.20.1">
      <FullProductName ProductID="curl-7.60.0-4.20.1">curl-7.60.0-4.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="curl-mini-7.60.0-4.20.1">
      <FullProductName ProductID="curl-mini-7.60.0-4.20.1">curl-mini-7.60.0-4.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl-devel-7.60.0-4.20.1">
      <FullProductName ProductID="libcurl-devel-7.60.0-4.20.1">libcurl-devel-7.60.0-4.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl-devel-32bit-7.60.0-4.20.1">
      <FullProductName ProductID="libcurl-devel-32bit-7.60.0-4.20.1">libcurl-devel-32bit-7.60.0-4.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl-devel-64bit-7.60.0-4.20.1">
      <FullProductName ProductID="libcurl-devel-64bit-7.60.0-4.20.1">libcurl-devel-64bit-7.60.0-4.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl-mini-devel-7.60.0-4.20.1">
      <FullProductName ProductID="libcurl-mini-devel-7.60.0-4.20.1">libcurl-mini-devel-7.60.0-4.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl4-32bit-7.60.0-4.20.1">
      <FullProductName ProductID="libcurl4-32bit-7.60.0-4.20.1">libcurl4-32bit-7.60.0-4.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl4-64bit-7.60.0-4.20.1">
      <FullProductName ProductID="libcurl4-64bit-7.60.0-4.20.1">libcurl4-64bit-7.60.0-4.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl4-mini-7.60.0-4.20.1">
      <FullProductName ProductID="libcurl4-mini-7.60.0-4.20.1">libcurl4-mini-7.60.0-4.20.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sles12sp4:latest">
      <FullProductName ProductID="Container suse/sles12sp4:latest:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of Container suse/sles12sp4:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-Azure-BYOS">
      <FullProductName ProductID="Image SLES12-SP4-Azure-BYOS:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of Image SLES12-SP4-Azure-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-Azure-BYOS">
      <FullProductName ProductID="Image SLES12-SP4-Azure-BYOS:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of Image SLES12-SP4-Azure-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-EC2-HVM-BYOS">
      <FullProductName ProductID="Image SLES12-SP4-EC2-HVM-BYOS:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of Image SLES12-SP4-EC2-HVM-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-EC2-HVM-BYOS">
      <FullProductName ProductID="Image SLES12-SP4-EC2-HVM-BYOS:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of Image SLES12-SP4-EC2-HVM-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-GCE-BYOS">
      <FullProductName ProductID="Image SLES12-SP4-GCE-BYOS:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of Image SLES12-SP4-GCE-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-GCE-BYOS">
      <FullProductName ProductID="Image SLES12-SP4-GCE-BYOS:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of Image SLES12-SP4-GCE-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-Azure">
      <FullProductName ProductID="Image SLES12-SP4-SAP-Azure:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-Azure">
      <FullProductName ProductID="Image SLES12-SP4-SAP-Azure:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-Azure-BYOS">
      <FullProductName ProductID="Image SLES12-SP4-SAP-Azure-BYOS:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-Azure-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-Azure-BYOS">
      <FullProductName ProductID="Image SLES12-SP4-SAP-Azure-BYOS:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-Azure-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-EC2-HVM">
      <FullProductName ProductID="Image SLES12-SP4-SAP-EC2-HVM:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-EC2-HVM">
      <FullProductName ProductID="Image SLES12-SP4-SAP-EC2-HVM:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-EC2-HVM-BYOS">
      <FullProductName ProductID="Image SLES12-SP4-SAP-EC2-HVM-BYOS:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-EC2-HVM-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-EC2-HVM-BYOS">
      <FullProductName ProductID="Image SLES12-SP4-SAP-EC2-HVM-BYOS:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-EC2-HVM-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-GCE">
      <FullProductName ProductID="Image SLES12-SP4-SAP-GCE:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-GCE">
      <FullProductName ProductID="Image SLES12-SP4-SAP-GCE:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-GCE-BYOS">
      <FullProductName ProductID="Image SLES12-SP4-SAP-GCE-BYOS:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-GCE-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP4-SAP-GCE-BYOS">
      <FullProductName ProductID="Image SLES12-SP4-SAP-GCE-BYOS:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of Image SLES12-SP4-SAP-GCE-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-32bit-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:libcurl4-32bit-7.60.0-4.20.1">libcurl4-32bit-7.60.0-4.20.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-32bit-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:libcurl4-32bit-7.60.0-4.20.1">libcurl4-32bit-7.60.0-4.20.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-32bit-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:libcurl4-32bit-7.60.0-4.20.1">libcurl4-32bit-7.60.0-4.20.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:curl-7.60.0-4.20.1">curl-7.60.0-4.20.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:libcurl4-7.60.0-4.20.1">libcurl4-7.60.0-4.20.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-32bit-7.60.0-4.20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:libcurl4-32bit-7.60.0-4.20.1">libcurl4-32bit-7.60.0-4.20.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.</Note>
    </Notes>
    <CVE>CVE-2020-8231</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/sles12sp4:latest:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-Azure-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-Azure-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-EC2-HVM-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-EC2-HVM-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-GCE-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-GCE-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:libcurl4-7.60.0-4.20.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211786-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-8231.html</URL>
        <Description>CVE-2020-8231</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1175109</URL>
        <Description>SUSE Bug 1175109</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179399</URL>
        <Description>SUSE Bug 1179399</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186108</URL>
        <Description>SUSE Bug 1186108</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.</Note>
    </Notes>
    <CVE>CVE-2020-8284</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/sles12sp4:latest:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-Azure-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-Azure-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-EC2-HVM-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-EC2-HVM-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-GCE-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-GCE-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:libcurl4-7.60.0-4.20.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211786-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-8284.html</URL>
        <Description>CVE-2020-8284</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179398</URL>
        <Description>SUSE Bug 1179398</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179399</URL>
        <Description>SUSE Bug 1179399</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186108</URL>
        <Description>SUSE Bug 1186108</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.</Note>
    </Notes>
    <CVE>CVE-2020-8285</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/sles12sp4:latest:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-Azure-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-Azure-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-EC2-HVM-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-EC2-HVM-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-GCE-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-GCE-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:libcurl4-7.60.0-4.20.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211786-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-8285.html</URL>
        <Description>CVE-2020-8285</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179399</URL>
        <Description>SUSE Bug 1179399</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186108</URL>
        <Description>SUSE Bug 1186108</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.</Note>
    </Notes>
    <CVE>CVE-2020-8286</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/sles12sp4:latest:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-Azure-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-Azure-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-EC2-HVM-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-EC2-HVM-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-GCE-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-GCE-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:libcurl4-7.60.0-4.20.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211786-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-8286.html</URL>
        <Description>CVE-2020-8286</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179593</URL>
        <Description>SUSE Bug 1179593</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186108</URL>
        <Description>SUSE Bug 1186108</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.</Note>
    </Notes>
    <CVE>CVE-2021-22876</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/sles12sp4:latest:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-Azure-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-Azure-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-EC2-HVM-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-EC2-HVM-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-GCE-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-GCE-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:libcurl4-7.60.0-4.20.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211786-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-22876.html</URL>
        <Description>CVE-2021-22876</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1183933</URL>
        <Description>SUSE Bug 1183933</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.</Note>
    </Notes>
    <CVE>CVE-2021-22898</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/sles12sp4:latest:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-Azure-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-Azure-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-EC2-HVM-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-EC2-HVM-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-GCE-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-GCE-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-Azure:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-EC2-HVM:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE-BYOS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE-BYOS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE:curl-7.60.0-4.20.1</ProductID>
        <ProductID>Image SLES12-SP4-SAP-GCE:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:libcurl4-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:curl-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:libcurl4-32bit-7.60.0-4.20.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:libcurl4-7.60.0-4.20.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211786-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-22898.html</URL>
        <Description>CVE-2021-22898</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186114</URL>
        <Description>SUSE Bug 1186114</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1192450</URL>
        <Description>SUSE Bug 1192450</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
