{"id":"CVE-2016-7141","details":"curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.","aliases":["CURL-CVE-2016-7141"],"modified":"2026-09-10T03:45:05.152663484Z","published":"2016-10-03T21:59:08.300Z","related":["SUSE-SU-2016:2330-1","SUSE-SU-2016:2449-1","SUSE-SU-2016:2700-1","SUSE-SU-2017:2699-1","SUSE-SU-2017:2700-1","SUSE-SU-2018:0230-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"42.1"},{"last_affected":"42.1"}],"source":"CPE_STRING","vendor_product":"opensuse:leap"}]},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2018/11/msg00005.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2016-09/msg00094.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-2575.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-2957.html"},{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/92754"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1036739"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:3558"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201701-47"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1373229"},{"type":"FIX","url":"https://curl.haxx.se/docs/adv_20160907.html"},{"type":"FIX","url":"https://github.com/curl/curl/commit/curl-7_50_2~32"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/curl/curl","events":[{"introduced":"0"},{"last_affected":"a448dcbdb3b60481bce26e6783099e5bf3bce3aa"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"7.50.1"}]}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-7141.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}