CVE-2025-0167

ADVISORY - debian

Summary

When asked to use a .netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a default entry that omits both login and password. A rare circumstance.


EPSS Score: 0.00062 (0.199)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Debian

CREATED

UPDATED

ADVISORY IDCVE-2025-0167
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/curldebdebian12<7.88.1-10+deb12u117.88.1-10+deb12u11
debian/curldebdebianunstable<8.12.0+git20250209.89ed161+ds-18.12.0+git20250209.89ed161+ds-1
debian/curldebdebian13<8.12.0+git20250209.89ed161+ds-18.12.0+git20250209.89ed161+ds-1

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

ADVISORY IDCVE-2025-0167
EXPLOITABILITY SCORE

1.6

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

3.4low

Alpine

CREATED

UPDATED

ADVISORY IDCVE-2025-0167
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

Ubuntu

CREATED

UPDATED

ADVISORY IDCVE-2025-0167
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow

Chainguard

CREATED

UPDATED

ADVISORY ID

CGA-gr5c-pjrp-3fmw

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

Photon

CREATED

UPDATED

ADVISORY ID

CVE-2025-0167

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

5.3medium