Credentials management in cURL - CVE-2016-8616
Published: August 1, 2018 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.
Affected software
Amazon Linux AMI
Arch Linux
SUSE Linux
Slackware Linux
Fedora
Opensuse
curl (Alpine package)
curl
Dell EMC Unisphere Central
How to mitigate CVE-2016-8616
curl (Alpine package) - addressed in versions 7.49.1-r4, 7.51.0-r0
Dell EMC Unisphere Central - update to 4.0.8.23220
curl - addressed in versions 7.47.1-9.fc24, 7.51.0-1.fc25
External References
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/94094
- http://www.securitytracker.com/id/1037192
- https://access.redhat.com/errata/RHSA-2018:2486
- https://access.redhat.com/errata/RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8616
- https://curl.haxx.se/CVE-2016-8616.patch
- https://curl.haxx.se/docs/adv_20161102B.html
- https://security.gentoo.org/glsa/201701-47
- https://www.tenable.com/security/tns-2016-21
Related Security Bulletins
- Credentials management in curl.haxx.se cURL
- OpenSUSE Linux update for curl
- SUSE Linux update for curl
- SUSE Linux update for curl
- Credentials management in curl (Alpine package)
- Arch Linux update for lib32-libcurl-gnutls
- Arch Linux update for libcurl-gnutls
- Arch Linux update for libcurl-compat
- Arch Linux update for curl
- Arch Linux update for lib32-libcurl-compat
- Arch Linux update for lib32-curl
- Amazon Linux AMI update for curl
- Slackware Linux update for curl
- Multiple vulnerabilities in Dell EMC Unisphere Central
- Fedora 24 update for curl
- Fedora 25 update for curl