Vulnerability CVE-2016-8625: Information
Description
curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.
Severity: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
curl | sisyphus | 7.51.0-alt1 | 8.7.1-alt2 | ALT-PU-2016-2231-1 | 171758 | Fixed |
curl | p10 | 7.51.0-alt1 | 8.7.1-alt2 | ALT-PU-2016-2231-1 | 171758 | Fixed |
curl | p9 | 7.51.0-alt1 | 7.79.0-alt2 | ALT-PU-2016-2231-1 | 171758 | Fixed |
curl | p8 | 7.52.1-alt1.M80P.1 | 7.65.0-alt1 | ALT-PU-2016-2480-1 | 175378 | Fixed |
curl | c10f1 | 7.51.0-alt1 | 8.6.0-alt1 | ALT-PU-2016-2231-1 | 171758 | Fixed |
curl | c9f2 | 7.51.0-alt1 | 8.6.0-alt1 | ALT-PU-2016-2231-1 | 171758 | Fixed |
curl | c7 | 7.56.1-alt1.M70C.1.1 | 7.56.1-alt1.M70C.1.1 | ALT-PU-2018-1442-1 | 202075 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://curl.haxx.se/docs/adv_20161102K.html |
|
https://curl.haxx.se/CVE-2016-8625.patch |
|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8625 |
|
https://www.tenable.com/security/tns-2016-21 |
|
GLSA-201701-47 |
|
1037192 |
|
94107 |
|
RHSA-2018:2486 |
|
RHSA-2018:3558 |
|
[bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8 | |
[bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8 |