cbcvebase.
CVE-2017-7468
published 2018-07-16

CVE-2017-7468: In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changed. That is…

PriorityP335high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
0.35%
57.8th percentile
In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changed. That is unacceptable since a server by specification is allowed to skip the client certificate check on resume, and may instead use the old identity which was established by the previous certificate (or no certificate). libcurl supports by default the use of TLS session id/ticket to resume previous TLS sessions to speed up subsequent TLS handshakes. They are used when for any reason an existing TLS connection couldn't be kept alive to make the next handshake faster. This flaw is a regression and identical to CVE-2016-5419 reported on August 3rd 2016, but affecting a different version range.

Affected

7 ranges
VendorProductVersion rangeFixed in
applemacos_sierra_10.12.6_security_update_2017-003_el_capitan_and_security_update_201
debiancurl< curl 7.52.1-5 (bookworm)curl 7.52.1-5 (bookworm)
haxxcurl>= 0 < 7.52.1-57.52.1-5
haxxcurl>= 0 < 7.52.1-57.52.1-5
haxxcurl>= 0 < 7.52.1-57.52.1-5
haxxcurl>= 0 < 7.52.1-57.52.1-5
haxxlibcurl7.52.0 – 7.53.1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.