Описание
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
Релиз | Статус | Примечание |
---|---|---|
devel | released | 7.38.0-3ubuntu2.2 |
esm-infra-legacy/trusty | not-affected | 7.35.0-1ubuntu2.5 |
lucid | ignored | end of life |
precise | released | 7.22.0-3ubuntu4.14 |
trusty | released | 7.35.0-1ubuntu2.5 |
trusty/esm | not-affected | 7.35.0-1ubuntu2.5 |
upstream | released | 7.42.0 |
utopic | released | 7.37.1-1ubuntu3.4 |
vivid | released | 7.38.0-3ubuntu2.2 |
vivid/stable-phone-overlay | released | 7.38.0-3ubuntu2.2 |
Показывать по
EPSS
5 Medium
CVSS2
Связанные уязвимости
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM c ...
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
EPSS
5 Medium
CVSS2