CVE-2016-8624
Summary
curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with a '#' character, and could instead be tricked into connecting to a different host. This may have security implications if you for example use an URL parser that follows the RFC to check for allowed domains before using curl to request them.
Impact & exploitability
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8624 ↗
Additional information
- NVD record
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8624Patch
- https://curl.haxx.se/docs/adv_20161102J.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/94103Advisory
- http://www.securitytracker.com/id/1037192Advisory
- https://access.redhat.com/errata/RHSA-2018:2486Advisory
- https://access.redhat.com/errata/RHSA-2018:3558
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E