PT-2016-6416 · Curl+5 · Libcurl+6

Bru Rom

·

Publicado

2016-08-03

·

Atualizado

2026-05-18

·

CVE-2016-5419

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions curl and libcurl versions prior to 7.50.1
Description The issue allows remote attackers to bypass intended restrictions by resuming a TLS session even when the client certificate has changed. This is because libcurl would attempt to resume a TLS session even if the client certificate had changed, which is unacceptable since a server may skip the client certificate check on resume and use the old identity established by the previous certificate. libcurl supports the use of TLS session id/ticket to resume previous TLS sessions, which can be used to speed up subsequent TLS handshakes.
Recommendations For versions prior to 7.50.1, update to version 7.50.1 or later to resolve the issue. As a temporary workaround, consider disabling TLS session resumption until a patch is available. Restrict access to sensitive resources that rely on client certificate authentication to minimize the risk of exploitation. Avoid using TLS session id/ticket in the affected libcurl versions until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1895
ALT-PU-2017-1492
ALT-PU-2018-2456
CESA-2016_2575
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2016-5419
DLA-586-1
DSA-3638-1
MGASA-2016-0285
RHSA-2016:2575
RHSA-2016_2575
RHSA-2018:3558
SUSE-SU-2016:2155-1
SUSE-SU-2016:2330-1
SUSE-SU-2016:2449-1
SUSE-SU-2016_2330-1
SUSE-SU-2016_2449-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-3048-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Curl
Libcurl