ftp,imap,pop3,smtp: reject STARTTLS server response pipelining

If a server pipelines future responses within the STARTTLS response, the
former are preserved in the pingpong cache across TLS negotiation and
used as responses to the encrypted commands.

This fix detects pipelined STARTTLS responses and rejects them with an
error.

CVE-2021-22947

Bug: https://curl.se/docs/CVE-2021-22947.html
This commit is contained in:
Patrick Monnerat 2021-09-07 13:26:42 +02:00 committed by Daniel Stenberg
parent 364f174724
commit 8ef147c436
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
9 changed files with 236 additions and 1 deletions

57
tests/data/test982 Normal file
View file

@ -0,0 +1,57 @@
<testcase>
<info>
<keywords>
POP3
STARTTLS
</keywords>
</info>
#
# Server-side
<reply>
<servercmd>
CAPA STLS USER
REPLY STLS -ERR currently unavailable\r\n+OK user accepted\r\n+OK authenticated
REPLY PASS -ERR Authentication credentials invalid
</servercmd>
<data nocheck="yes">
From: me@somewhere
To: fake@nowhere
body
--
yours sincerely
</data>
</reply>
#
# Client-side
<client>
<features>
SSL
</features>
<server>
pop3
</server>
<name>
POP3 STARTTLS pipelined server response
</name>
<command>
pop3://%HOSTIP:%POP3PORT/%TESTNUMBER -u user:secret --ssl
</command>
</client>
#
# Verify data after the test has been "shot"
<verify>
# 8 is CURLE_WEIRD_SERVER_REPLY
<errorcode>
8
</errorcode>
<protocol>
CAPA
STLS
</protocol>
</verify>
</testcase>