Описание
curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.
It was found that the libcurl library using the NSS (Network Security Services) library as TLS/SSL backend incorrectly re-used client certificates for subsequent TLS connections in certain cases. An attacker could potentially use this flaw to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
.NET Core 1.0 on Red Hat Enterprise Linux | rh-dotnetcore10-curl | Not affected | ||
.NET Core 1.1 on Red Hat Enterprise Linux | rh-dotnetcore11-curl | Not affected | ||
.NET Core 2.0 on Red Hat Enterprise Linux | rh-dotnet20-curl | Not affected | ||
Red Hat Enterprise Linux 5 | curl | Not affected | ||
Red Hat Enterprise Linux 6 | curl | Will not fix | ||
Red Hat Enterprise Virtualization 3 | mingw-virt-viewer | Will not fix | ||
Red Hat JBoss Enterprise Web Server 3 | curl | Affected | ||
Red Hat Enterprise Linux 7 | curl | Fixed | RHSA-2016:2575 | 03.11.2016 |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | httpd24-curl | Fixed | RHSA-2018:3558 | 13.11.2018 |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | httpd24-httpd | Fixed | RHSA-2018:3558 | 13.11.2018 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.2 Medium
CVSS3
4.9 Medium
CVSS2
Связанные уязвимости
curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.
curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.
curl and libcurl before 7.50.2, when built with NSS and the libnsspem. ...
curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.
EPSS
4.2 Medium
CVSS3
4.9 Medium
CVSS2