Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-2192

Опубликовано: 07 июл. 2011
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3

Описание

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

РелизСтатусПримечание
devel

not-affected

7.21.6-3ubuntu2
hardy

released

7.18.0-1ubuntu2.3
lucid

released

7.19.7-1ubuntu1.1
maverick

released

7.21.0-1ubuntu1.1
natty

released

7.21.3-1ubuntu1.2
upstream

released

7.21.7,7.21.6-2

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 15 лет назад

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

nvd
около 15 лет назад

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

debian
около 15 лет назад

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10. ...

github
около 4 лет назад

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

oracle-oval
около 15 лет назад

ELSA-2011-0918: curl security update (MODERATE)

4.3 Medium

CVSS2