CVE Published: 01/08/2018 |
CVE Updated: 06/08/2024 |
CVE Year: 2016 Source: redhat |
Vendor: The Curl Project |
Product: curl Status : PUBLISHED
CVE-2016-8616 Description
A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.