CVE Vulnerabilities

CVE-2016-8616

DEPRECATED: Authentication Bypass Issues

Published: Aug 01, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V3
3.7 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.

Weakness

This weakness has been deprecated because it covered redundant concepts already described in CWE-287.

Affected Software

NameVendorStart VersionEnd Version
CurlHaxx*7.51.0 (excluding)
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHathttpd24-curl-0:7.61.1-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHathttpd24-httpd-0:2.4.34-7.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHathttpd24-nghttp2-0:1.7.1-7.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHathttpd24-curl-0:7.61.1-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHathttpd24-httpd-0:2.4.34-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHathttpd24-nghttp2-0:1.7.1-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHathttpd24-curl-0:7.61.1-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHathttpd24-httpd-0:2.4.34-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHathttpd24-nghttp2-0:1.7.1-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHathttpd24-curl-0:7.61.1-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHathttpd24-httpd-0:2.4.34-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHathttpd24-nghttp2-0:1.7.1-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHathttpd24-curl-0:7.61.1-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHathttpd24-httpd-0:2.4.34-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHathttpd24-nghttp2-0:1.7.1-7.el7*
Text-Only JBCSRedHatjbcs-httpd24-curl*
CurlUbuntudevel*
CurlUbuntuesm-infra-legacy/trusty*
CurlUbuntuesm-infra/xenial*
CurlUbuntuprecise*
CurlUbuntutrusty*
CurlUbuntutrusty/esm*
CurlUbuntuupstream*
CurlUbuntuvivid/stable-phone-overlay*
CurlUbuntuvivid/ubuntu-core*
CurlUbuntuxenial*
CurlUbuntuyakkety*
CurlUbuntuzesty*

References