CVE-2016-7141
Last modified
CVE-2016-7141 is a vulnerability of currently unknown severity. curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.. EPSS estimates a 8.40% chance of exploitation in the next 30 days.
Description
curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opensuse | Leap | 42.1 |
| Haxx | Libcurl | <= 7.50.1 |
References
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00094.htmlThird Party Advisory
- http://www.securityfocus.com/bid/92754Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036739Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1373229Issue Tracking
- https://curl.haxx.se/docs/adv_20160907.htmlPatch, Vendor Advisory
- https://github.com/curl/curl/commit/curl-7_50_2~32Issue Tracking, Patch
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00094.htmlThird Party Advisory
- http://www.securityfocus.com/bid/92754Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036739Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1373229Issue Tracking
- https://curl.haxx.se/docs/adv_20160907.htmlPatch, Vendor Advisory
- https://github.com/curl/curl/commit/curl-7_50_2~32Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-7141?
How severe is CVE-2016-7141?
How do I fix CVE-2016-7141?
Are you affected by CVE-2016-7141?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
