CVE-2016-9953

Description

The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly have unspecified other impact via a wildcard certificate name, which triggers an out-of-bounds read.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.854

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2016-9586,CVE-2016-9952,CVE-2016-9953 are affected in Curl For Windows 7.51.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.51.0Windows
Vulnerabilities CVE-2016-9586,CVE-2016-9952,CVE-2016-9953 are fixed in Curl For Windows 7.52.0Windows
Out-of-bounds Read Vulnerability (CVE-2016-9953)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234