[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2016-7141Date: (C)2016-10-05   (M)2024-02-22


curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.5CVSS Score : 5.0
Exploit Score: 3.9Exploit Score: 10.0
Impact Score: 3.6Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: NONE
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: NONEAvailability: NONE
Integrity: HIGH 
Availability: NONE 
  
Reference:
SECTRACK-1036739
BID-92754
GLSA-201701-47
RHSA-2016:2575
RHSA-2016:2957
RHSA-2018:3558
https://lists.debian.org/debian-lts-announce/2018/11/msg00005.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
https://bugzilla.redhat.com/show_bug.cgi?id=1373229
https://curl.haxx.se/docs/adv_20160907.html
https://github.com/curl/curl/commit/curl-7_50_2~32
openSUSE-SU-2016:2379

CWE    1
CWE-287
OVAL    13
oval:org.secpod.oval:def:89045192
oval:org.secpod.oval:def:703341
oval:org.secpod.oval:def:38513
oval:org.secpod.oval:def:204134
...

© SecPod Technologies