Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3148

Опубликовано: 22 апр. 2015
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.

It was discovered that libcurl could incorrectly reuse Negotiate authenticated HTTP connections for subsequent requests. If an application using libcurl established a Negotiate authenticated HTTP connection to a server and sent subsequent requests with different credentials, the connection could be re-used with the initial set of credentials instead of using the new ones.

Отчет

This issue affects the version of curl package as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This issue is not planned to be addressed in a future update for Red Hat Enterprise Linux 5.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.2curlWill not fix
Red Hat Enterprise Linux 5curlWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerFix deferred
Red Hat Enterprise Linux 6curlFixedRHSA-2015:125420.07.2015
Red Hat Enterprise Linux 7curlFixedRHSA-2015:215919.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1213351curl: Negotiate not treated as connection-oriented

EPSS

Процентиль: 80%
0.01442
Низкий

4 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.

nvd
больше 10 лет назад

cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.

debian
больше 10 лет назад

cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenti ...

github
больше 3 лет назад

cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.

suse-cvrf
больше 10 лет назад

Security update for curl

EPSS

Процентиль: 80%
0.01442
Низкий

4 Medium

CVSS2