First published: Mon Apr 23 2018(Updated: )
curl before version 7.52.1 is vulnerable to an uninitialized random in libcurl's internal function that returns a good 32bit random value. Having a weak or virtually non-existent random value makes the operations that use it vulnerable.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Curl | <7.52.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9594 is classified as a medium severity vulnerability due to the potential for weak randomness in cryptographic operations.
To fix CVE-2016-9594, upgrade to curl version 7.52.1 or later.
CVE-2016-9594 can lead to predictability in cryptographic operations, increasing vulnerability to attacks.
CVE-2016-9594 may be exploited remotely if an application uses curl for network operations.
CVE-2016-9594 affects all versions of curl before 7.52.1.