Improper Authentication in cURL - CVE-2016-7141

 

Improper Authentication in cURL - CVE-2016-7141

Published: October 4, 2016 / Updated: July 28, 2020


Vulnerability identifier: #VU32242
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7141
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.


Affected software

cURL
curl (Alpine package)
System x Integrated Management Module (IMM2)
Flex System Integrated Management Module (IMM2)
Integrated Management Module II (IMM2) for BladeCenter Systems

How to mitigate CVE-2016-7141

Install update from vendor's website.

cURL - update to 7.50.2
curl (Alpine package) - update to 7.49.1-r2
System x Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Flex System Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO84C-6.80-bc

External References

Related Security Bulletins