curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.
References
Link | Resource |
---|---|
https://curl.haxx.se/docs/adv_20161102K.html | Patch Vendor Advisory |
https://curl.haxx.se/CVE-2016-8625.patch | Patch Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8625 | Issue Tracking Patch Third Party Advisory |
https://www.tenable.com/security/tns-2016-21 | Third Party Advisory |
https://security.gentoo.org/glsa/201701-47 | Third Party Advisory |
http://www.securitytracker.com/id/1037192 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/94107 | Third Party Advisory VDB Entry |
https://access.redhat.com/errata/RHSA-2018:2486 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2018:3558 | Third Party Advisory |
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E | |
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E |
Configurations
Information
Published : 2018-07-31 23:29
Updated : 2021-06-29 08:15
NVD link : CVE-2016-8625
Mitre link : CVE-2016-8625
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
haxx
- curl