Amazon Linux AMI : curl (ALAS-2016-742)
High Nessus Plugin ID 93743
SynopsisThe remote Amazon Linux AMI host is missing a security update.
DescriptionAfter testing original CVE-2016-5420 patch, it was discovered that libcurl built on top of NSS (Network Security Services) still incorrectly re-uses client certificates if a certificate from file is used for one TLS connection but no certificate is set for a subsequent TLS connection.
SolutionRun 'yum update curl' to update your system.