Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-0755

Опубликовано: 27 янв. 2016
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5curlWill not fix
Red Hat Enterprise Linux 6curlWill not fix
Red Hat Enterprise Linux 7curlWill not fix
Red Hat JBoss Enterprise Web Server 3curlWill not fix
Red Hat Software Collectionshttpd24-curlNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1302263curl: NTLM credentials not-checked for proxy connection re-use

EPSS

Процентиль: 61%
0.00412
Низкий

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 10 лет назад

The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.

CVSS3: 7.3
nvd
около 10 лет назад

The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.

CVSS3: 7.3
debian
около 10 лет назад

The ConnectionExists function in lib/url.c in libcurl before 7.47.0 do ...

suse-cvrf
около 10 лет назад

Security update for curl

suse-cvrf
около 10 лет назад

Security update for curl

EPSS

Процентиль: 61%
0.00412
Низкий

4 Medium

CVSS2