Cryptographic issues in cURL - CVE-2016-5419

 

Cryptographic issues in cURL - CVE-2016-5419

Published: August 10, 2016 / Updated: July 28, 2020


Vulnerability identifier: #VU32263
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5419
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.


Affected software

cURL
Arch Linux
Amazon Linux AMI
Slackware Linux
Fedora
curl (Alpine package)
curl
Flex System EN6131 40Gb Ethernet / IB6131 40Gb Infiniband Switch Firmware
QLogic Virtual Fabric Extension Module for IBM BladeCenter
Flex System FC3171 8Gb SAN Switch

How to mitigate CVE-2016-5419

Install update from vendor's website.

cURL - update to 7.50.1
curl (Alpine package) - addressed in versions 7.49.1-r1, 7.50.1-r0
Flex System EN6131 40Gb Ethernet / IB6131 40Gb Infiniband Switch Firmware - update to 3.6.6000
curl - addressed in versions 7.43.0-8.fc23, 7.47.1-6.fc24
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.19.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.9.02.00

External References

Related Security Bulletins