Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jvc-33pv-cq2m

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

EPSS

Процентиль: 80%
0.0151
Низкий

Связанные уязвимости

ubuntu
почти 14 лет назад

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

redhat
около 14 лет назад

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

nvd
почти 14 лет назад

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

debian
почти 14 лет назад

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10. ...

oracle-oval
почти 14 лет назад

ELSA-2011-0918: curl security update (MODERATE)

EPSS

Процентиль: 80%
0.0151
Низкий