CVE-2016-5420: High severity Google Android vulnerability

Published Aug 1, 2016
·
Updated

curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.

Other sources

It was found that the libcurl library did not check the client certificate when choosing the TLS connection to reuse. An attacker could potentially use this flaw to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.

It was reported that libcurl did not consider client certificates when reusing TLS connections. libcurl supports reuse of established connections for subsequent requests. It does this by keeping a few previous connections "alive" in a connection pool so that a subsequent request that can use one of them instead of creating a new connection will do so.

When using a client certificate for a connection that was then put into the connection pool, that connection could then wrongly get reused in a subsequent request to that same server that either didn't use a client certificate at all or that asked to use a different client certificate thus trying to tell the user that it is a different entity.

This mistakenly using the wrong connection could of course lead to applications sending requests to the wrong realms of the server using authentication that it wasn't supposed to have for those operations.

External Reference:

https://curl.haxx.se/docs/adv20160803B.html

Red Hat

Affected Software

12 affected componentsFixes available
redhat/curl<0:7.29.0-35.el7
0:7.29.0-35.el7
redhat/httpd24-curl<0:7.61.1-1.el6
0:7.61.1-1.el6
redhat/httpd24-httpd<0:2.4.34-7.el6
0:2.4.34-7.el6
redhat/httpd24-nghttp2<0:1.7.1-7.el6
0:1.7.1-7.el6
redhat/httpd24-curl<0:7.61.1-1.el7
0:7.61.1-1.el7
redhat/httpd24-httpd<0:2.4.34-7.el7
0:2.4.34-7.el7
redhat/httpd24-nghttp2<0:1.7.1-7.el7
0:1.7.1-7.el7
redhat/curl<7.50.1
7.50.1
Google Android
Debian Debian Linux=8.0
haxx libcurl<=7.50.0
openSUSE Leap=42.1

Event History

Aug 1, 2016
Data Sourced
via Red Hat·01:32 PM
DescriptionSeverityAffected Software
Aug 3, 2016
CVE Published
12:00 AM
Aug 10, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Dec 5, 2016
Data Sourced
via Android·12:00 AM
SeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2016-5420?

CVE-2016-5420 has been classified as a medium severity vulnerability.

2

How do I fix CVE-2016-5420?

To address CVE-2016-5420, upgrade curl and libcurl to version 7.50.1 or later.

3

What software is affected by CVE-2016-5420?

CVE-2016-5420 affects curl and libcurl versions prior to 7.50.1 across various distributions.

4

Can CVE-2016-5420 allow for remote attacks?

Yes, CVE-2016-5420 may allow remote attackers to hijack authentication of connections.

5

What authentication mechanism is vulnerable in CVE-2016-5420?

CVE-2016-5420 involves a vulnerability in the TLS connection mechanism related to client certificates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203