Описание
A flaw in the libcurl SASL negotiation for LDAP authentication allows an
incomplete handshake sequence to be misinterpreted as a successful
cryptographic verification. An attacker executing a Man-in-the-Middle (MITM)
attack can inject a premature or shortcut response that bypasses complete peer
validation.
A flaw was found in libcurl's SASL (Simple Authentication and Security Layer) negotiation for LDAP (Lightweight Directory Access Protocol) authentication when using the OpenLDAP backend. An incomplete handshake sequence can be misinterpreted as a successful cryptographic verification. A remote attacker, by performing a Man-in-the-Middle (MITM) attack, could inject a premature response to bypass complete peer validation, leading to an authentication bypass.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Confidential Compute Attestation | build-of-trustee/trustee-rhel9 | Under investigation | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-payload-rhel9 | Under investigation | ||
| Red Hat Enterprise Linux 10 | curl | Under investigation | ||
| Red Hat Enterprise Linux 10 | igvm | Under investigation | ||
| Red Hat Enterprise Linux 10 | rust | Under investigation | ||
| Red Hat Enterprise Linux 10 | s390utils | Under investigation | ||
| Red Hat Enterprise Linux 10 | snphost | Under investigation | ||
| Red Hat Enterprise Linux 10 | trustee | Under investigation | ||
| Red Hat Enterprise Linux 6 | curl | Under investigation | ||
| Red Hat Enterprise Linux 7 | curl | Under investigation |
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.
A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.
A flaw in the libcurl SASL negotiation for LDAP authentication allows ...
A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.
EPSS
3.7 Low
CVSS3