REDHAT-BUG-1373229: Low severity curl libcurl vulnerability
After testing original CVE-2016-5420 patch, it was discovered that libcurl built on top of NSS (Network Security Services) still incorrectly re-uses client certificates if a certificate from file is used for one TLS connection but no certificate is set for a subsequent TLS connection.
The original patch for CVE-2016-5420 has been amended to also contain the attached patch:
https://curl.haxx.se/CVE-2016-5420.patch
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1373229?
The severity of REDHAT-BUG-1373229 is critical due to the potential for client certificate re-use vulnerabilities leading to unauthorized access.
How do I fix REDHAT-BUG-1373229?
To fix REDHAT-BUG-1373229, ensure you are using the latest version of libcurl with the appropriate patches applied.
What software is affected by REDHAT-BUG-1373229?
REDHAT-BUG-1373229 affects libcurl and Mozilla Network Security Services (NSS) configurations.
What vulnerabilities does REDHAT-BUG-1373229 relate to?
REDHAT-BUG-1373229 is associated with CVE-2016-5420, which addresses issues with client certificate re-use.
Is there a workaround for REDHAT-BUG-1373229?
A temporary workaround for REDHAT-BUG-1373229 includes explicitly managing the client certificates to avoid re-use.