CVE Database
/

CVE-2016-7141

Back to search

CVE-2016-7141

Published: Oct 3, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2016:2575
vendor-advisory
x_refsource_REDHAT
RHSA-2018:3558
vendor-advisory
x_refsource_REDHAT
1036739
vdb-entry
x_refsource_SECTRACK
openSUSE-SU-2016:2379
vendor-advisory
x_refsource_SUSE
RHSA-2016:2957
vendor-advisory
x_refsource_REDHAT
92754
vdb-entry
x_refsource_BID
GLSA-201701-47
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now