CVE-2016-8619

critical
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.

References

http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html

http://www.securityfocus.com/bid/94100

http://www.securitytracker.com/id/1037192

https://access.redhat.com/errata/RHSA-2018:2486

https://access.redhat.com/errata/RHSA-2018:3558

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8619

https://curl.haxx.se/CVE-2016-8619.patch

https://curl.haxx.se/docs/adv_20161102E.html

https://security.gentoo.org/glsa/201701-47

https://www.tenable.com/security/tns-2016-21

Details

Source: MITRE

Published: 2018-08-01

Updated: 2019-10-09

Type: CWE-415

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*

Tenable Plugins

View all (22 total)

IDNameProductFamilySeverity
140168OracleVM 3.4 : curl (OVMSA-2020-0035)NessusOracleVM Local Security Checks
critical
131701Juniper Junos Space < 19.2R1 Multiple Vulnerabilities (JSA10951)NessusJunos Local Security Checks
critical
125380Oracle Linux 6 / 7 : curl (ELSA-2019-4652)NessusOracle Linux Local Security Checks
critical
125003EulerOS Virtualization 3.0.1.0 : curl (EulerOS-SA-2019-1550)NessusHuawei Local Security Checks
critical
105468F5 Networks BIG-IP : cURL and libcurl vulnerability (K46123931)NessusF5 Networks Local Security Checks
critical
99930Oracle Secure Global Desktop Multiple Vulnerabilities (April 2017 CPU) (SWEET32)NessusMisc.
critical
99881EulerOS 2.0 SP1 : curl (EulerOS-SA-2017-1036)NessusHuawei Local Security Checks
critical
99880EulerOS 2.0 SP2 : curl (EulerOS-SA-2017-1035)NessusHuawei Local Security Checks
critical
96644GLSA-201701-47 : cURL: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
95917macOS 10.12.x < 10.12.2 Multiple VulnerabilitiesNessusMacOS X Local Security Checks
high
9826cURL/libcurl 7.x < 7.51.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
95009Fedora 25 : curl (2016-89769648a0)NessusFedora Local Security Checks
critical
94941Debian DLA-711-1 : curl security updateNessusDebian Local Security Checks
critical
94752openSUSE Security Update : curl (openSUSE-2016-1280)NessusSuSE Local Security Checks
critical
94686Amazon Linux AMI : curl (ALAS-2016-766)NessusAmazon Linux Local Security Checks
critical
94592Fedora 24 : curl (2016-e8e8cdb4ed)NessusFedora Local Security Checks
critical
94588Debian DSA-3705-1 : curl - security updateNessusDebian Local Security Checks
critical
94574Ubuntu 12.04 LTS / 14.04 LTS / 16.04 LTS / 16.10 : curl vulnerabilities (USN-3123-1)NessusUbuntu Local Security Checks
critical
94572SUSE SLES11 Security Update : curl (SUSE-SU-2016:2714-1)NessusSuSE Local Security Checks
critical
94516Slackware 13.0 / 13.1 / 13.37 / 14.0 / 14.1 / 14.2 / current : curl (SSA:2016-308-01)NessusSlackware Local Security Checks
critical
94506SUSE SLED12 / SLES12 Security Update : curl (SUSE-SU-2016:2699-1)NessusSuSE Local Security Checks
critical
94493FreeBSD : cURL -- multiple vulnerabilities (765feb7d-a0d1-11e6-a881-b499baebfeaf)NessusFreeBSD Local Security Checks
critical