CVE-2016-8625
Publication date 1 August 2018
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.
Status
Package | Ubuntu Release | Status |
---|---|---|
curl | 20.04 LTS focal |
Not affected
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial | Ignored intrusive fix | |
14.04 LTS trusty | Ignored intrusive fix | |
Notes
mdeslaur
upstream patch switched from libidn to libidn2 and may be causing issues, see: https://curl.haxx.se/mail/lib-2016-11/0033.html http://seclists.org/oss-sec/2016/q4/333 Fixing this is intrusive and is likely to cause regressions in stable releases. As such, we will not be fixing this issue in Ubuntu 16.04 LTS and earlier.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 · High |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | High |
Availability impact | None |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |