CVE-2016-8625

NameCVE-2016-8625
Descriptioncurl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
curl (PTS)jessie7.38.0-4+deb8u11vulnerable
jessie (security)7.38.0-4+deb8u16vulnerable
stretch, stretch (security)7.52.1-5+deb9u9fixed
buster7.64.0-4fixed
bullseye, sid7.65.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
curlsource(unstable)7.51.0-1medium

Notes

[jessie] - curl <no-dsa> (the fix is too invasive)
[wheezy] - curl <no-dsa> (the fix is too invasive)
https://github.com/curl/curl/commit/9c91ec778104ae3b744b39444d544e82d5ee9ece
https://curl.haxx.se/docs/adv_20161102K.html
https://curl.haxx.se/CVE-2016-8625.patch

Search for package or bug name: Reporting problems