ALPINE-CVE-2016-8616 PUBLISHED CVSS 5.900000095367432 MEDIUM

A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.

Risk Scores

CVSS v3.0
5.900000095367432
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Alpine:v3.13curl0, 7.50.3-r1, 7.50.3-r0
Alpine:v3.12curl0, 0, 7.19.2-r0
Alpine:v3.23curl0, 7.50.3-r1, 7.50.3-r0
Alpine:v3.15curl0, 7.19.2-r1, 7.19.4-r0
Alpine:v3.19curl7.19.2-r0, 7.50.3-r1, 7.50.3-r0
Alpine:v3.21curl7.19.2-r0, 0, 7.50.3-r1
Alpine:v3.9curl0, 7.19.2-r0, 7.19.2-r1
Alpine:v3.4curl7.43.0-r0, 0, 7.19.2-r0
Alpine:v3.20curl7.19.2-r0, 7.50.3-r1, 7.50.3-r0
Alpine:v3.17curl0, 7.39.0-r0, 7.40.0-r0
Alpine:v3.6curl7.46.0-r2, 0, 7.19.2-r0
Alpine:v3.14curl7.19.6-r0, 0, 7.50.3-r1
Alpine:v3.8curl7.50.3-r1, 7.40.0-r0, 7.39.0-r0
Alpine:v3.16curl7.21.7-r0, 7.21.7-r1, 7.21.7-r2
Alpine:v3.2curl7.19.2-r0, 7.29.0-r0, 7.30.0-r0
Alpine:v3.5curl7.19.4-r0, 7.50.3-r1, 7.50.3-r0
Alpine:v3.22curl7.37.1-r0, 7.39.0-r0, 7.40.0-r0
Alpine:v3.18curl7.21.7-r0, 7.37.0-r0, 7.36.0-r0
Alpine:v3.3curl7.28.0-r0, 0, 7.49.1-r3
Alpine:v3.11curl7.19.6-r0, 7.19.7-r0, 7.19.7-r1

…and 2 more

Timeline

References

Open in Interactive Console →