Логотип exploitDog
bind:"CVE-2016-7141" OR bind:"CVE-2016-5419" OR bind:"CVE-2016-5420"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2016-7141" OR bind:"CVE-2016-5419" OR bind:"CVE-2016-5420"

Количество 22

Количество 22

github логотип

GHSA-qpjh-642g-hgh8

больше 3 лет назад

curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-j5mq-cppw-g9w7

больше 3 лет назад

curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-qpjh-642g-hgh8

curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-j5mq-cppw-g9w7

curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу