CVE-2016-7141Improper Authentication in Libcurl

Severity
7.5HIGHNVD
EPSS
0.5%
top 33.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 3
Latest updateMay 14

Description

curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDhaxx/libcurl7.50.1
Debianhaxx/curl< 7.51.0-1+3
Ubuntuhaxx/curl< 7.35.0-1ubuntu2.10+1
NVDopensuse/leap42.1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-vx32-35rm-8jq5: curl and libcurl before 72022-05-14
OSV
curl vulnerabilities2016-11-03
OSV
CVE-2016-7141: curl and libcurl before 72016-10-03
CVEList
CVE-2016-7141: curl and libcurl before 72016-10-03

📋Vendor Advisories

4
Apple
CVE-2016-7141: macOS Sierra 10.12.2, Security Update 2016-003 El Capitan, and Security Update 2016-007 Yosemite2016-12-13
Ubuntu
curl vulnerabilities2016-11-03
Red Hat
curl: Incorrect reuse of client certificates2016-09-05
Debian
CVE-2016-7141: curl - curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library...2016

💬Community

4
Bugzilla
CVE-2016-7141 mingw-curl: curl: Incorrect reuse of client certificates [fedora-all]2016-09-05
Bugzilla
CVE-2016-7141 curl: Incorrect reuse of client certificates [fedora-all]2016-09-05
Bugzilla
CVE-2016-7141 curl: Incorrect reuse of client certificates2016-09-05
Bugzilla
CVE-2016-7141 mingw-curl: curl: Incorrect reuse of client certificates [epel-7]2016-09-05
CVE-2016-7141 — Improper Authentication in Haxx Libcurl | cvebase