CVE-2016-8616DEPRECATED: Authentication Bypass Issues in Curl

Severity
5.9MEDIUMNVD
CNA3.7
EPSS
4.1%
top 11.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateMay 13

Description

A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

NVDhaxx/curl< 7.51.0
Debianhaxx/curl< 7.51.0-1+3
CVEListV5the_curl_project/curl7.51.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-22qv-x7vv-h86h: A flaw was found in curl before version 72022-05-13
CVEList
CVE-2016-8616: A flaw was found in curl before version 72018-08-01
OSV
CVE-2016-8616: A flaw was found in curl before version 72018-08-01

📋Vendor Advisories

4
Apple
CVE-2016-8616: macOS Sierra 10.12.2, Security Update 2016-003 El Capitan, and Security Update 2016-007 Yosemite2016-12-13
Ubuntu
curl vulnerabilities2016-11-03
Red Hat
curl: Case insensitive password comparison2016-11-02
Debian
CVE-2016-8616: curl - A flaw was found in curl before version 7.51.0 When re-using a connection, curl ...2016

💬Community

4
Bugzilla
CVE-2016-8615 CVE-2016-8616 CVE-2016-8617 CVE-2016-8618 CVE-2016-8619 CVE-2016-8620 CVE-2016-8621 CVE-2016-8622 CVE-2016-8623 CVE-2016-8624 CVE-2016-8625 mingw-curl: various flaws [epel-7]2016-11-02
Bugzilla
CVE-2016-8615 CVE-2016-8616 CVE-2016-8617 CVE-2016-8618 CVE-2016-8619 CVE-2016-8620 CVE-2016-8621 CVE-2016-8622 CVE-2016-8623 CVE-2016-8624 CVE-2016-8625 mingw-curl: various flaws [fedora-all]2016-11-02
Bugzilla
CVE-2016-8615 CVE-2016-8616 CVE-2016-8617 CVE-2016-8618 CVE-2016-8619 CVE-2016-8620 CVE-2016-8621 CVE-2016-8622 CVE-2016-8623 CVE-2016-8624 curl: various flaws [fedora-all]2016-11-02
Bugzilla
CVE-2016-8616 curl: Case insensitive password comparison2016-10-25
CVE-2016-8616 — Haxx Curl vulnerability | cvebase