CVE-2016-5420
Summary
| CVE | CVE-2016-5420 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-08-10 14:59:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate. |
Risk And Classification
Primary CVSS: v3.0 7.5 HIGH from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS: 0.145960000 probability, percentile 0.962700000 (date 2026-07-21)
Problem Types: CWE-285 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CPU Oct 2018 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| [SECURITY] Fedora 24 Update: curl-7.47.1-6.fc24 - package-announce - Fedora Mailing-Lists | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [R7] LCE 4.8.1 Fixes Multiple Vulnerabilities - Security Advisory | Tenable™ | af854a3a-2127-422b-91ae-364da2661108 | www.tenable.com | |
| openSUSE-SU-2016:2379-1: moderate: Security update for curl | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| curl - Re-using connections with wrong client cert | af854a3a-2127-422b-91ae-364da2661108 | curl.haxx.se | Mitigation, Patch, Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| USN-3048-1: curl vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| cURL/libcurl Certificate Reuse Bug Lets Remote Users Bypass Security Restrictions on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Android Security Bulletin—December 2016 | Android Open Source Project | af854a3a-2127-422b-91ae-364da2661108 | source.android.com | |
| cURL/libcurl TLS Connection Reuse Bug Lets Remote Users Bypass Security Restrictions on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| openSUSE-SU-2016:2227-1: moderate: Security update for curl | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [SECURITY] Fedora 23 Update: curl-7.43.0-8.fc23 - package-announce - Fedora Mailing-Lists | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| cURL/libcURL CVE-2016-5420 Certificate Validation Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| cURL: Multiple vulnerabilities (GLSA 201701-47) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Debian -- Security Information -- DSA-3638-1 curl | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| The Slackware Linux Project: Slackware Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.slackware.com | |
| [SECURITY] Fedora 24 Update: curl-7.47.1-6.fc24 - package-announce - Fedora Mailing-Lists | MITRE | lists.fedoraproject.org | |
| [SECURITY] Fedora 23 Update: curl-7.43.0-8.fc23 - package-announce - Fedora Mailing-Lists | MITRE | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.