cbcvebase.
CVE-2016-5420
published 2016-08-10

CVE-2016-5420: curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the…

PriorityP351high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
14.60%
96.2th percentile
curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.

Affected

18 ranges
VendorProductVersion rangeFixed in
applemacos_sierra_10.12.2_security_update_2016-003_el_capitan_and_security_update_201
debiancurl< curl 7.51.0-1 (bookworm)curl 7.51.0-1 (bookworm)
debiancurl< curl 7.50.1-1 (bookworm)curl 7.50.1-1 (bookworm)
debiandebian_linux
googleandroid
haxxcurl>= 0 < 7.51.0-17.51.0-1
haxxcurl>= 0 < 7.50.1-17.50.1-1
haxxcurl>= 0 < 7.51.0-17.51.0-1
haxxcurl>= 0 < 7.50.1-17.50.1-1
haxxcurl>= 0 < 7.51.0-17.51.0-1
haxxcurl>= 0 < 7.50.1-17.50.1-1
haxxcurl>= 0 < 7.51.0-17.51.0-1
haxxcurl>= 0 < 7.50.1-17.50.1-1
haxxcurl>= 0 < 7.35.0-1ubuntu2.87.35.0-1ubuntu2.8
haxxcurl>= 0 < 7.47.0-1ubuntu2.17.47.0-1ubuntu2.1
haxxlibcurl<= 7.50.1
haxxlibcurl<= 7.50.0
opensuseleap

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.