Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-2628

Опубликовано: 12 мар. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was introduced in RHEL 6.7 and affects RHEL 6 curl only.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:haxx:curl:7.19.7:*:*:*:*:*:*:*

Одно из

cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

EPSS

Процентиль: 74%
0.00831
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was introduced in RHEL 6.7 and affects RHEL 6 curl only.

CVSS3: 4.8
redhat
больше 8 лет назад

curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was introduced in RHEL 6.7 and affects RHEL 6 curl only.

CVSS3: 9.8
debian
больше 7 лет назад

curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-5 ...

CVSS3: 9.8
github
больше 3 лет назад

curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was introduced in RHEL 6.7 and affects RHEL 6 curl only.

oracle-oval
больше 8 лет назад

ELSA-2017-0847: curl security update (MODERATE)

EPSS

Процентиль: 74%
0.00831
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287
NVD-CWE-noinfo