CVE-2025-0167
ADVISORY - ubuntuSummary
When asked to use a .netrc
file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a default
entry that omits both login and password. A rare circumstance.
Ubuntu
CREATED
UPDATED
ADVISORY IDCVE-2025-0167
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AlowPackage | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
---|---|---|---|---|---|
ubuntu/curl | deb | ubuntu | 22.04 | >=0 | Not yet available |
ubuntu/curl | deb | ubuntu | 24.10 | >=0 | Not yet available |
ubuntu/curl | deb | ubuntu | 24.04 | >=0 | Not yet available |
ubuntu/curl | deb | ubuntu | 25.04 | >=0 | Not yet available |
Severity and metrics
No CVSS data available from this advisory.
NIST
CREATED
UPDATED
ADVISORY IDCVE-2025-0167
EXPLOITABILITY SCORE
1.6
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
3.4lowAlpine
CREATED
UPDATED
ADVISORY IDCVE-2025-0167
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Debian
CREATED
UPDATED
ADVISORY IDCVE-2025-0167
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AlowChainguard
CREATED
UPDATED
ADVISORY ID
CGA-gr5c-pjrp-3fmw
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Photon
CREATED
UPDATED
ADVISORY ID
CVE-2025-0167
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-