Candidate: CVE-2016-8625 PublicDate: 2018-08-01 06:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8625 https://curl.haxx.se/docs/adv_20161102K.html Description: curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host. Ubuntu-Description: Notes: mdeslaur> upstream patch switched from libidn to libidn2 and may be mdeslaur> causing issues, see: mdeslaur> https://curl.haxx.se/mail/lib-2016-11/0033.html mdeslaur> http://seclists.org/oss-sec/2016/q4/333 mdeslaur> mdeslaur> Fixing this is intrusive and is likely to cause regressions in mdeslaur> stable releases. As such, we will not be fixing this issue in mdeslaur> Ubuntu 16.04 LTS and earlier. Bugs: Priority: low Discovered-by: Christian Heimes Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_curl: upstream: https://github.com/curl/curl/commit/9c91ec778104ae3b744b39444d544e82d5ee9ece upstream_curl: released (7.51.0) precise_curl: ignored (reached end-of-life) precise/esm_curl: ignored trusty_curl: ignored (reached end-of-life) trusty/esm_curl: ignored (intrusive fix) vivid/stable-phone-overlay_curl: ignored (reached end-of-life) vivid/ubuntu-core_curl: ignored (reached end-of-life) xenial_curl: ignored (intrusive fix) esm-infra/xenial_curl: ignored (intrusive fix) yakkety_curl: ignored (reached end-of-life) zesty_curl: not-affected (7.52.1-4ubuntu1.4) artful_curl: not-affected (7.55.1-1ubuntu2.2) bionic_curl: not-affected (7.55.1-1ubuntu2.1) cosmic_curl: not-affected (7.55.1-1ubuntu2.1) disco_curl: not-affected (7.55.1-1ubuntu2.1) eoan_curl: not-affected (7.55.1-1ubuntu2.1) focal_curl: not-affected (7.55.1-1ubuntu2.1) devel_curl: not-affected (7.55.1-1ubuntu2.1)