First published: Mon Aug 01 2016(Updated: )
curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/curl | <7.50.1 | 7.50.1 |
Google Android | ||
haxx libcurl | <=7.50.0 | |
Debian Debian Linux | =8.0 | |
openSUSE | =42.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.