Vulnerability in Libcurl 8.20.0 and older on the SiteMinder Policy Server r12.8.8.1 and older
search cancel

Vulnerability in Libcurl 8.20.0 and older on the SiteMinder Policy Server r12.8.8.1 and older

book

Article ID: 437690

calendar_today

Updated On:

Products

SITEMINDER

Issue/Introduction

The Policy Server bundles Libcurl in the binaries.  The following versions of Libcurl are shipped with the Policy Server:

Policy Server r12.8.7:     LibCurl 7.84.0
Policy Server r12.8.8:     LibCurl 8.4.0
Policy Server r12.8.8.1:  LibCurl 8.4.0
Policy Server r12.9:        LibCurl 8.12.1.0

KB378171 delivered LibCurl 8.10.0 

 

NOTE: This KB only applies to Policy Server r12.8.8.1 and older.   For the 12.9 Policy Servers use KB 451429 Vulnerabilities in Libcurl 8.20.0 and older in the SiteMinder r12.9 Policy Server

 

Environment

PRODUCT: Symantec Siteminder

COMPONENT: Policy Server

VERSIONS: r12.8.7; r12.8.8; r12.8.8.1

OPERATING SYSTEM: Any

Cause

The following CVE's have been published for LibCurl 7.84.0 - 8.18.0.

Common Vulnerability Enumeration (CVE)DESCRIPTION1st VERSION IMPACTEDLAST VERSION IMPACTEDREMEDIATED
CVE-2026-12064proto-default skips SSH verification7.81.08.20.08.21.0
CVE-2026-11856cross-origin Digest auth state leak7.10.68.20.08.21.0
CVE-2026-9547SSH improper host validation7.69.08.20.08.21.0
CVE-2026-8932incomplete mTLS config matching in conn reuse7.78.20.08.21.0
CVE-2026-8927env-set cross-proxy Digest auth state leak7.12.08.20.08.21.0
CVE-2026-8924trailing dot domain super cookie7.46.08.20.08.21.0
CVE-2026-8458wrong reuse for different services7.43.08.20.08.21.0
CVE-2026-8286wrong STARTTLS connection reuse7.30.08.20.08.21.0
CVE-2026-7168cross-proxy Digest auth state leak7.12.08.19.08.20.0 - 8.21.0
CVE-2026-6429netrc credential leak with reused proxy connection7.14.08.19.08.20.0 - 8.21.0
CVE-2026-6276stale custom cookie host causes cookie leak7.71.08.19.08.20.0 - 8.21.0
CVE-2026-6253proxy credentials leak over redirect-to proxy7.14.18.19.08.20.0 - 8.21.0
CVE-2026-5773wrong reuse of SMB connection7.40.08.19.08.20.0 - 8.21.0
CVE-2026-5545wrong reuse of HTTP Negotiate connection7.10.68.19.08.20.0 - 8.21.0
CVE-2026-4873connection reuse ignores TLS requirement7.20.08.19.08.20.0 - 8.21.0
CVE-2026-3784wrong proxy connection reuse with credentials7.78.18.08.19.0 - 8.21.0
CVE-2026-3783token leak with redirect and netrc7.33.08.18.08.19.0 - 8.21.0
CVE-2026-1965bad reuse of HTTP Negotiate connection7.10.68.18.08.19.0 - 8.21.0
CVE-2025-15224libssh key passphrase bypass without agent set7.58.08.17.08.18.0 - 8.21.0
CVE-2025-15079libssh global known_hosts override7.58.08.17.08.18.0 - 8.21.0
CVE-2025-14524bearer token leak on cross-protocol redirect7.33.08.17.08.18.0 - 8.21.0
CVE-2025-14017broken TLS options for threaded LDAPS7.17.08.17.08.18.0 - 8.21.0
CVE-2025-10966missing SFTP host verification with wolfSSH7.69.08.16.08.17.0 - 8.21.0
CVE-2025-0725gzip integer overflow7.10.58.11.18.12.0 - 8.21.0
CVE-2025-0167netrc and default credential leak7.76.08.11.18.12.0 - 8.21.0
CVE-2024-11053netrc and redirect credential leak7.76.08.11.08.12.0 - 8.21.0
CVE-2024-9681HSTS subdomain overwrites parent cache entry7.74.08.10.18.11.0 - 8.21.0
CVE-2024-8096OCSP stapling bypass with GnuTLS7.41.08.9.18.10.0 - 8.21.0
CVE-2024-7264ASN.1 date parser overread7.32.08.9.08.10.0 - 8.21.0
CVE-2024-2398HTTP/2 push headers memory-leak7.44.08.6.08.7.0 - 8.21.0
CVE-2023-46219HSTS long filename clears contents7.84.08.4.08.5.0 - 8.21.0
CVE-2023-46218cookie mixed case PSL bypass7.46.08.4.08.5.0 - 8.21.0
CVE-2023-38546CVE-2023-38546cookie injection with none file7.9.18.3.08.4.0 - 8.21.0
CVE-2023-38545SOCKS5 heap buffer overflow7.69.08.3.08.4.0 - 8.21.0
CVE-2023-38039HTTP headers eat all memory7.84.08.2.18.3.0 - 8.21.0
CVE-2023-28322more POST-after-PUT confusion7.78.0.18.1.0 - 8.21.0
CVE-2023-28321IDN wildcard match7.12.08.0.18.1.0 - 8.21.0
CVE-2023-28320siglongjmp race condition7.9.88.0.18.1.0 - 8.21.0
CVE-2023-28319UAF in SSH sha256 fingerprint check7.81.08.0.18.1.0 - 8.21.0
CVE-2023-27538SSH connection too eager reuse still7.16.17.88.18.0.0 - 8.21.0
CVE-2023-27536GSS delegation too eager connection reuse7.22.07.88.18.0.0 - 8.21.0
CVE-2023-27535FTP too eager connection reuse7.13.07.88.18.0.0 - 8.21.0
CVE-2023-27534SFTP path ~ resolving discrepancy7.18.07.88.18.0.0 - 8.21.0
CVE-2023-27533TELNET option IAC injection7.77.88.18.0.0 - 8.21.0
CVE-2023-23916HTTP multi-header compression denial of service7.57.07.87.07.88.0 - 8.21.0
CVE-2023-23915HSTS amnesia with --parallel7.77.07.87.07.88.0 - 8.21.0
CVE-2023-23914HSTS ignored on multiple requests7.77.07.87.07.88.0 - 8.21.0
CVE-2022-43552HTTP Proxy deny use after free7.16.07.86.07.87.0 - 8.21.0
CVE-2022-43551Another HSTS bypass via IDN7.77.07.86.07.87.0 - 8.21.0
CVE-2022-42916HSTS bypass via IDN7.77.07.85.07.87.0 - 8.21.0
CVE-2022-42915HTTP proxy double free7.77.07.85.07.87.0 - 8.21.0
CVE-2022-35260.netrc parser out-of-bounds access7.84.07.85.07.86.0 - 8.21.0
CVE-2022-32221POST following PUT confusion7.77.85.07.86.0 - 8.21.0
CVE-2022-35252control code in cookie denial of service4.97.84.07.85.0 - 8.21.0

Resolution

Using this KB you can upgrade LibCurl on the r12.8.8.1 and older SiteMinder Policy Server to LibCurl 8.17.0.  LibCurl 8.17.0 has been attached to this KB.

NOTE:  There are a number of LibCurl vulnerabilities published which LibCurl 8.17.0 does not remediate.  Those CVE's are printed in red in the list above.

It is advised that to remediate all LibCurl CVE's you upgrade the SiteMinder Policy Server to r12.9 or higher.   

SiteMinder r12.8.8.1 and older along with LibCurl 8.17.0 and older are both built on OpenSSL 1.0.2.  SiteMinder r12.9 and higher along with LibCurl 8.18.0 and higher are both built on OpenSSL 3.0.x.  Neither OpenSSL 3.0.x nor LibCurl 8.18.0 are backwards compatible with SiteMinder Policy Server r12.8.8.1 and older.

Upgrading to Libcurl 8.17.0 will still leave the system vulnerable to the following CVE's:

Common Vulnerability Enumeration (CVE)DESCRIPTION1st VERSION IMPACTEDLAST VERSION IMPACTEDREMEDIATED
CVE-2026-12064proto-default skips SSH verification7.81.08.20.08.21.0
CVE-2026-11856cross-origin Digest auth state leak7.10.68.20.08.21.0
CVE-2026-9547SSH improper host validation7.69.08.20.08.21.0
CVE-2026-8932incomplete mTLS config matching in conn reuse7.78.20.08.21.0
CVE-2026-8927env-set cross-proxy Digest auth state leak7.12.08.20.08.21.0
CVE-2026-8924trailing dot domain super cookie7.46.08.20.08.21.0
CVE-2026-8458wrong reuse for different services7.43.08.20.08.21.0
CVE-2026-8286wrong STARTTLS connection reuse7.30.08.20.08.21.0
CVE-2026-7168cross-proxy Digest auth state leak7.12.08.19.08.20.0 - 8.21.0
CVE-2026-6429netrc credential leak with reused proxy connection7.14.08.19.08.20.0 - 8.21.0
CVE-2026-6276stale custom cookie host causes cookie leak7.71.08.19.08.20.0 - 8.21.0
CVE-2026-6253proxy credentials leak over redirect-to proxy7.14.18.19.08.20.0 - 8.21.0
CVE-2026-5773wrong reuse of SMB connection7.40.08.19.08.20.0 - 8.21.0
CVE-2026-5545wrong reuse of HTTP Negotiate connection7.10.68.19.08.20.0 - 8.21.0
CVE-2026-4873connection reuse ignores TLS requirement7.20.08.19.08.20.0 - 8.21.0
CVE-2026-3784wrong proxy connection reuse with credentials7.78.18.08.19.0 - 8.21.0
CVE-2026-3783token leak with redirect and netrc7.33.08.18.08.19.0 - 8.21.0
CVE-2026-1965bad reuse of HTTP Negotiate connection7.10.68.18.08.19.0 - 8.21.0

Upgrade SiteMinder r12.8.8.1 or Older to LibCurl 8.17.0

LINUX 

1) Download 'libcurl_8.17.0_12.8.x_linux.zip' to the SiteMinder Policy Server

2) Decompress 'libcurl_8.17.0_libs.zip'

Contents:

libcurl.so
libcurl.so.4
libcurl.so.4.8.0

3) Stop the SiteMinder Policy Server

4) Backup and Delete, or Rename the following files:

/<Install_Dir>/CA/siteminder/lib/libcurl.so.4.8.0
/<Install_Dir>/CA/siteminder/lib/libcurl.so.4
/<Install_Dir>/CA/siteminder/lib/libcurl.so

5) Copy the following files from 'libcurl_8.17.0_12.8.x_linux.zip' into the '/<Install_Dir>/CA/siteminder/lib/' directory.

libcurl.so
libcurl.so.4
libcurl.so.4.8.0

6) Start the SiteMinder Policy Server

WINDOWS

1) Download 'libcurl_8.17.0_12.8.x_win64.zip' to the SiteMinder Policy Server

2) Decompress 'libcurl_8.17.0_12.8.x_win64.zip'

3) Stop the SiteMinder Policy Server

4) Backup and Delete, or Rename the following files:

<Install_Dir>\CA\siteminder\bin\libcurl.dll

5) Copy the following files from 'libcurl_8.17.0_12.8.x_win64' into the '<Install_Dir>\CA\siteminder\bin\' directory.

libcurl.dll

6) Start the SiteMinder Policy Server

Additional Information

curl and libcurl vulnerabilities

KB 451429 Vulnerabilities in Libcurl 8.20.0 and older in the SiteMinder r12.9 Policy Server

Libcurl 8.20.0 and older is impacted by the following CVE's:

CVE-2026-12064
CVE-2026-11856
CVE-2026-9547
CVE-2026-8932
CVE-2026-8927
CVE-2026-8924
CVE-2026-8458
CVE-2026-8286
CVE-2026-7168
CVE-2026-6429
CVE-2026-6276
CVE-2026-6253
CVE-2026-5773
CVE-2026-5545
CVE-2026-4873
CVE-2026-3784
CVE-2026-3783
CVE-2026-1965
CVE-2025-15224
CVE-2025-15079
CVE-2025-14524
CVE-2025-14017
CVE-2025-10966
CVE-2025-0725
CVE-2025-0167
CVE-2024-11053
CVE-2024-9681
CVE-2024-8096
CVE-2024-7264
CVE-2024-2398
CVE-2023-46219
CVE-2023-46218
CVE-2023-38546
CVE-2023-38545
CVE-2023-38039
CVE-2023-28322
CVE-2023-28321
CVE-2023-28320
CVE-2023-28319
CVE-2023-27538
CVE-2023-27536
CVE-2023-27535
CVE-2023-27534
CVE-2023-27533
CVE-2023-23916
CVE-2023-23915
CVE-2023-23914
CVE-2022-43552
CVE-2022-43551
CVE-2022-42916
CVE-2022-42915
CVE-2022-35260
CVE-2022-32221
CVE-2022-35252

Attachments

libcurl_8.17.0_12.8.x_linux.zip get_app
libcurl_8.17.0_12.8.x_win64.zip get_app