CVE-2016-7141: High severity openSUSE Leap vulnerability
After testing original CVE-2016-5420 patch, it was discovered that libcurl built on top of NSS (Network Security Services) still incorrectly re-uses client certificates if a certificate from file is used for one TLS connection but no certificate is set for a subsequent TLS connection.
The original patch for CVE-2016-5420 has been amended to also contain the attached patch:
https://curl.haxx.se/CVE-2016-5420.patch
Other sources
curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7141?
CVE-2016-7141 is considered a moderate severity vulnerability that can allow remote attack vectors.
How do I fix CVE-2016-7141?
To fix CVE-2016-7141, update curl or libcurl to version 7.50.2 or later.
Which versions of curl are affected by CVE-2016-7141?
CVE-2016-7141 affects curl and libcurl versions prior to 7.50.2 when built with NSS.
Can CVE-2016-7141 lead to unauthorized access?
Yes, CVE-2016-7141 allows remote attackers to potentially hijack authentication through reused client certificates.
What systems are vulnerable to CVE-2016-7141?
The vulnerable systems include openSUSE Leap 42.1 and libcurl versions up to 7.50.1.