CVE-2016-9953: Critical severity curl vulnerability
The verifycertificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly have unspecified other impact via a wildcard certificate name, which triggers an out-of-bounds read.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9953?
CVE-2016-9953 has a high severity rating due to its potential to cause denial of service and reveal sensitive information.
How do I fix CVE-2016-9953?
To fix CVE-2016-9953, update libcurl to a version newer than 7.51.0.
What software is affected by CVE-2016-9953?
CVE-2016-9953 affects libcurl versions 7.30.0 to 7.51.0 built for Windows CE.
Can CVE-2016-9953 lead to remote attacks?
Yes, CVE-2016-9953 allows remote attackers to exploit the vulnerability for various malicious purposes.
What specific function in libcurl is vulnerable in CVE-2016-9953?
The verify_certificate function in schannel.c is the specific function affected by CVE-2016-9953.