CVE-2016-5420
Last modified
CVE-2016-5420 is a vulnerability of currently unknown severity. curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.. EPSS estimates a 14.60% chance of exploitation in the next 30 days.
Description
curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 8.0 |
| Haxx | Libcurl | <= 7.50.0 |
| Opensuse | Leap | 42.1 |
References
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00094.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3638Third Party Advisory
- https://curl.haxx.se/docs/adv_20160803B.htmlMitigation, Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00094.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3638Third Party Advisory
- https://curl.haxx.se/docs/adv_20160803B.htmlMitigation, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-5420?
How severe is CVE-2016-5420?
How do I fix CVE-2016-5420?
Are you affected by CVE-2016-5420?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
