CVE Database
/

CVE-2016-8616

Back to search

CVE-2016-8616

Published: Aug 1, 2018

Modified: Aug 6, 2024

PUBLISHED

CVSS v3.0

3.7

LOW

Description

A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.

VendorProductVersions

The Curl Project

curl

affected
7.51.0

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

None

References

94094
vdb-entry
x_refsource_BID
RHSA-2018:3558
vendor-advisory
x_refsource_REDHAT
1037192
vdb-entry
x_refsource_SECTRACK
RHSA-2018:2486
vendor-advisory
x_refsource_REDHAT
GLSA-201701-47
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now