curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/94107 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1037192 | Third Party Advisory VDB Entry |
https://access.redhat.com/errata/RHSA-2018:2486 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2018:3558 | Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8625 | Issue Tracking Patch Third Party Advisory |
https://curl.haxx.se/CVE-2016-8625.patch | Patch Vendor Advisory |
https://curl.haxx.se/docs/adv_20161102K.html | Patch Vendor Advisory |
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E | |
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E | |
https://security.gentoo.org/glsa/201701-47 | Third Party Advisory |
https://www.tenable.com/security/tns-2016-21 | Third Party Advisory |
Configurations
History
29 Jun 2021, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2018-08-01 06:29
Updated : 2024-02-04 20:03
NVD link : CVE-2016-8625
Mitre link : CVE-2016-8625
CVE.ORG link : CVE-2016-8625
JSON object : View
Products Affected
haxx
- curl
CWE
CWE-20
Improper Input Validation