Cryptographic issues in cURL - CVE-2016-5419
Published: August 10, 2016 / Updated: July 28, 2020
Vulnerability identifier: #VU32263
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5419
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.
Affected software
cURL
Arch Linux
Amazon Linux AMI
Slackware Linux
Fedora
curl (Alpine package)
curl
Flex System EN6131 40Gb Ethernet / IB6131 40Gb Infiniband Switch Firmware
QLogic Virtual Fabric Extension Module for IBM BladeCenter
Flex System FC3171 8Gb SAN Switch
Arch Linux
Amazon Linux AMI
Slackware Linux
Fedora
curl (Alpine package)
curl
Flex System EN6131 40Gb Ethernet / IB6131 40Gb Infiniband Switch Firmware
QLogic Virtual Fabric Extension Module for IBM BladeCenter
Flex System FC3171 8Gb SAN Switch
How to mitigate CVE-2016-5419
Install update from vendor's website.
cURL - update to 7.50.1
curl (Alpine package) - addressed in versions 7.49.1-r1, 7.50.1-r0
Flex System EN6131 40Gb Ethernet / IB6131 40Gb Infiniband Switch Firmware - update to 3.6.6000
curl - addressed in versions 7.43.0-8.fc23, 7.47.1-6.fc24
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.19.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.9.02.00
curl (Alpine package) - addressed in versions 7.49.1-r1, 7.50.1-r0
Flex System EN6131 40Gb Ethernet / IB6131 40Gb Infiniband Switch Firmware - update to 3.6.6000
curl - addressed in versions 7.43.0-8.fc23, 7.47.1-6.fc24
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.19.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.9.02.00
External References
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00011.html
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00094.html
- http://rhn.redhat.com/errata/RHSA-2016-2575.html
- http://rhn.redhat.com/errata/RHSA-2016-2957.html
- http://www.debian.org/security/2016/dsa-3638
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/92292
- http://www.securityfocus.com/bid/92319
- http://www.securitytracker.com/id/1036538
- http://www.securitytracker.com/id/1038341
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.563059
- http://www.ubuntu.com/usn/USN-3048-1
- https://access.redhat.com/errata/RHSA-2018:3558
- https://curl.haxx.se/docs/adv_20160803A.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GLPXQQKURBQFM4XM6645VRPTOE2AWG33/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/K3GQH4V3XAQ5Z53AMQRDEC3C3UHTW7QR/
- https://security.gentoo.org/glsa/201701-47
- https://source.android.com/security/bulletin/2016-12-01.html
- https://www.tenable.com/security/tns-2016-18
Related Security Bulletins
- Cryptographic issues in curl.haxx.se cURL
- Cryptographic issues in curl (Alpine package)
- Arch Linux update for curl
- Amazon Linux AMI update for curl
- Slackware Linux update for curl
- Multiple vulnerabilities in IBM Flex System FC3171 8Gb SAN Switch and SAN Pass-thru and QLogic Virtual Fabric Extension Module for IBM BladeCenter
- Fedora 23 update for curl
- Fedora 24 update for curl
- Multiple vulnerabilities in IBM Flex System EN6131 40Gb Ethernet / IB6131 40Gb Infiniband Switch Firmware