ZeroHour

CVE-2016-5420

CVSS 3.0
7.5 high
EPSS
15%p96
Published
()
Modified
Description

curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.

Vendors
debianhaxxopensuse
Products
debian linux, libcurl, leap
Weakness
CWE-285
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.