CVE-2016-8625
Published: August 31, 2023Last modified: September 22, 2025
Description
curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score | 7.5 | 
| Attack Vector | NETWORK | 
| Attack complexity | LOW | 
| Privileges required | NONE | 
| User interaction | NONE | 
| Scope | UNCHANGED | 
| Confidentiality | NONE | 
| Integrity impact | HIGH | 
| Availability impact | NONE | 
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N | 
Status
| Product | Release | Package | Status | 
|---|---|---|---|
| Alpaquita Linux | 23 LTS | curl | Not affected (8.2.1-r0) | 
| Stream | curl | Not affected (8.2.1-r0) | 
References
- http://www.securityfocus.com/bid/94107
 - http://www.securitytracker.com/id/1037192
 - https://access.redhat.com/errata/RHSA-2018:2486
 - https://access.redhat.com/errata/RHSA-2018:3558
 - https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8625
 - https://curl.haxx.se/CVE-2016-8625.patch
 - https://curl.haxx.se/docs/adv_20161102K.html
 - https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
 - https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E
 - https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
 - https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E
 - https://security.gentoo.org/glsa/201701-47
 - https://www.tenable.com/security/tns-2016-21