A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.
References
Configurations
History
No history.
Information
Published : 2018-08-01 06:29
Updated : 2024-11-21 02:59
NVD link : CVE-2016-8616
Mitre link : CVE-2016-8616
CVE.ORG link : CVE-2016-8616
JSON object : View
Products Affected
haxx
- curl