In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changed. That is unacceptable since a server by specification is allowed to skip the client certificate check on resume, and may instead use the old identity which was established by the previous certificate (or no certificate). libcurl supports by default the use of TLS session id/ticket to resume previous TLS sessions to speed up subsequent TLS handshakes. They are used when for any reason an existing TLS connection couldn't be kept alive to make the next handshake faster. This flaw is a regression and identical to CVE-2016-5419 reported on August 3rd 2016, but affecting a different version range.
CVSS Details
- CVSS 3.1 Base Score: 4.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Jul 16, 2018 | Jul 16, 2018 |
| Apple Osx Curl | — | Upgrade macOS to the latest version | Jul 19, 2017 | Jul 19, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 16, 2018 |
| Debian | — | Upgrade curl | Jul 30, 2024 | Jul 16, 2018 |
| Freebsd | — | Upgrade curl | Apr 20, 2017 | Apr 20, 2017 |
| Gentoo Linux | — | Upgrade net-misc/curl. | Oct 30, 2017 | Sep 17, 2017 |
| Suse | — | Upgrade libcurl4-32bitUpgrade libcurl-develUpgrade curlUpgrade libcurl4 | May 20, 2018 | Apr 19, 2017 |
| Ubuntu | — | Upgrade libcurl3-gnutlsUpgrade libcurl3Upgrade libcurl3-nssUpgrade curl | Apr 21, 2017 | Apr 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub