CVE-2016-8625

NameCVE-2016-8625
Descriptioncurl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
curl (PTS)bullseye7.74.0-1.3+deb11u13fixed
bullseye (security)7.74.0-1.3+deb11u14fixed
bookworm7.88.1-10+deb12u8fixed
bookworm (security)7.88.1-10+deb12u5fixed
sid, trixie8.11.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
curlsource(unstable)7.51.0-1

Notes

[jessie] - curl <no-dsa> (the fix is too invasive)
[wheezy] - curl <no-dsa> (the fix is too invasive)
https://github.com/curl/curl/commit/9c91ec778104ae3b744b39444d544e82d5ee9ece
https://curl.haxx.se/docs/adv_20161102K.html
https://curl.haxx.se/CVE-2016-8625.patch

Search for package or bug name: Reporting problems