CURL-CVE-2016-7141
Dashboard / Vulnerabilities / CURL-CVE-2016-7141
Summary: Incorrect reuse of client certificates
Details: libcurl built on top of NSS (Network Security Services) incorrectly reused client certificates if a certificate from file was used for one TLS connection but no certificate set for a subsequent TLS connection. While the symptoms are similar to CVE-2016-5420 (Reusing connection with wrong client cert), this vulnerability was caused by an implementation detail of the NSS backend in libcurl, which is orthogonal to the cause of CVE-2016-5420.
References:
Affected packages
Package
Name:
Purl:
Affected ranges
Type: SEMVER
Events:
Introduced- 7.19.6
Fixed -7.50.2
Affected versions
7.50.1
7.50.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
