Vulnerability Description
curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Haxx | Curl | < 7.51.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/94107Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037192Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:2486Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3558Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8625Issue TrackingPatchThird Party Advisory
- https://curl.haxx.se/CVE-2016-8625.patchPatchVendor Advisory
- https://curl.haxx.se/docs/adv_20161102K.htmlPatchVendor Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e3
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8
- https://security.gentoo.org/glsa/201701-47Third Party Advisory
- https://www.tenable.com/security/tns-2016-21Third Party Advisory
- http://www.securityfocus.com/bid/94107Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037192Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:2486Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3558Third Party Advisory
FAQ
What is CVE-2016-8625?
CVE-2016-8625 is a vulnerability with a CVSS score of 5.3 (MEDIUM). curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong hos...
How severe is CVE-2016-8625?
CVE-2016-8625 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8625?
Check the references section above for vendor advisories and patch information. Affected products include: Haxx Curl.