Vulnerability CVE-2016-8624: Information

Description

curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with a '#' character, and could instead be tricked into connecting to a different host. This may have security implications if you for example use an URL parser that follows the RFC to check for allowed domains before using curl to request them.

Severity: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Published: Aug. 1, 2018
Modified: Nov. 7, 2023
Error type identifier: CWE-20

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
curlsisyphus7.51.0-alt18.7.1-alt2ALT-PU-2016-2231-1171758Fixed
curlp107.51.0-alt18.7.1-alt1ALT-PU-2016-2231-1171758Fixed
curlp97.51.0-alt17.79.0-alt2ALT-PU-2016-2231-1171758Fixed
curlp87.52.1-alt1.M80P.17.65.0-alt1ALT-PU-2016-2480-1175378Fixed
curlc10f17.51.0-alt18.6.0-alt1ALT-PU-2016-2231-1171758Fixed
curlc9f27.51.0-alt18.6.0-alt1ALT-PU-2016-2231-1171758Fixed
curlc77.56.1-alt1.M70C.1.17.56.1-alt1.M70C.1.1ALT-PU-2018-1442-1202075Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
      End excliding
      7.51.0