CVE-2016-8616
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 3.7epss 3.5%
probabilidad de explotación
3.5%top 12% de las CVE
explotación observada
noninguna fuente lo reporta
A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Productos afectados
The Curl Project · curlReferencias
https://access.redhat.com/errata/RHSA-2018:2486https://access.redhat.com/errata/RHSA-2018:3558https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8616https://curl.haxx.se/CVE-2016-8616.patchhttps://curl.haxx.se/docs/adv_20161102B.htmlhttps://security.gentoo.org/glsa/201701-47https://www.tenable.com/security/tns-2016-21http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/94094http://www.securitytracker.com/id/1037192