Red Hat Bugzilla – Bug 1373229
CVE-2016-7141 curl: Incorrect reuse of client certificates
Last modified: 2018-07-18 11:00:21 EDT
After testing original CVE-2016-5420 patch, it was discovered that libcurl built on top of NSS (Network Security Services) still incorrectly re-uses client certificates if a certificate from file is used for one TLS connection but no certificate is set for a subsequent TLS connection. The original patch for CVE-2016-5420 has been amended to also contain the attached patch: https://curl.haxx.se/CVE-2016-5420.patch
Created curl tracking bugs for this issue: Affects: fedora-all [bug 1373230]
Created mingw-curl tracking bugs for this issue: Affects: fedora-all [bug 1373231] Affects: epel-7 [bug 1373232]
CVE assignment: http://seclists.org/oss-sec/2016/q3/419
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2016:2575 https://rhn.redhat.com/errata/RHSA-2016-2575.html
This issue has been addressed in the following products: Via RHSA-2016:2957 https://rhn.redhat.com/errata/RHSA-2016-2957.html
External References: https://curl.haxx.se/docs/adv_20160907.html