mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-08-04 08:44:25 +00:00
119 lines
3.4 KiB
JSON
119 lines
3.4 KiB
JSON
{
|
|
"CVE_data_meta" : {
|
|
"ASSIGNER" : "psampaio@redhat.com",
|
|
"ID" : "CVE-2016-8625",
|
|
"STATE" : "PUBLIC"
|
|
},
|
|
"affects" : {
|
|
"vendor" : {
|
|
"vendor_data" : [
|
|
{
|
|
"product" : {
|
|
"product_data" : [
|
|
{
|
|
"product_name" : "curl",
|
|
"version" : {
|
|
"version_data" : [
|
|
{
|
|
"version_value" : "7.51.0"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"vendor_name" : "The Curl Project"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"data_format" : "MITRE",
|
|
"data_type" : "CVE",
|
|
"data_version" : "4.0",
|
|
"description" : {
|
|
"description_data" : [
|
|
{
|
|
"lang" : "eng",
|
|
"value" : "curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host."
|
|
}
|
|
]
|
|
},
|
|
"impact" : {
|
|
"cvss" : [
|
|
[
|
|
{
|
|
"vectorString" : "5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
|
|
"version" : "3.0"
|
|
}
|
|
],
|
|
[
|
|
{
|
|
"vectorString" : "4.3/AV:N/AC:M/Au:N/C:N/I:P/A:N",
|
|
"version" : "2.0"
|
|
}
|
|
]
|
|
]
|
|
},
|
|
"problemtype" : {
|
|
"problemtype_data" : [
|
|
{
|
|
"description" : [
|
|
{
|
|
"lang" : "eng",
|
|
"value" : "CWE-20"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"references" : {
|
|
"reference_data" : [
|
|
{
|
|
"name" : "https://curl.haxx.se/docs/adv_20161102K.html",
|
|
"refsource" : "CONFIRM",
|
|
"url" : "https://curl.haxx.se/docs/adv_20161102K.html"
|
|
},
|
|
{
|
|
"name" : "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8625",
|
|
"refsource" : "CONFIRM",
|
|
"url" : "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8625"
|
|
},
|
|
{
|
|
"name" : "https://curl.haxx.se/CVE-2016-8625.patch",
|
|
"refsource" : "CONFIRM",
|
|
"url" : "https://curl.haxx.se/CVE-2016-8625.patch"
|
|
},
|
|
{
|
|
"name" : "https://www.tenable.com/security/tns-2016-21",
|
|
"refsource" : "CONFIRM",
|
|
"url" : "https://www.tenable.com/security/tns-2016-21"
|
|
},
|
|
{
|
|
"name" : "GLSA-201701-47",
|
|
"refsource" : "GENTOO",
|
|
"url" : "https://security.gentoo.org/glsa/201701-47"
|
|
},
|
|
{
|
|
"name" : "RHSA-2018:2486",
|
|
"refsource" : "REDHAT",
|
|
"url" : "https://access.redhat.com/errata/RHSA-2018:2486"
|
|
},
|
|
{
|
|
"name" : "RHSA-2018:3558",
|
|
"refsource" : "REDHAT",
|
|
"url" : "https://access.redhat.com/errata/RHSA-2018:3558"
|
|
},
|
|
{
|
|
"name" : "94107",
|
|
"refsource" : "BID",
|
|
"url" : "http://www.securityfocus.com/bid/94107"
|
|
},
|
|
{
|
|
"name" : "1037192",
|
|
"refsource" : "SECTRACK",
|
|
"url" : "http://www.securitytracker.com/id/1037192"
|
|
}
|
|
]
|
|
}
|
|
}
|