Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3236

Опубликовано: 17 июн. 2015
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors.

Отчет

This issue did not affect the versions of curl as shipped with Red Hat Enterprise Linux 5, 6, and 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.1curlNot affected
Red Hat Ceph Storage 1.2curlNot affected
Red Hat Enterprise Linux 5curlNot affected
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=1233816curl: lingering HTTP credentials in connection re-use

EPSS

Процентиль: 89%
0.04525
Низкий

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors.

nvd
больше 10 лет назад

cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors.

debian
больше 10 лет назад

cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authenticat ...

github
больше 3 лет назад

cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors.

EPSS

Процентиль: 89%
0.04525
Низкий

2.6 Low

CVSS2