Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-0755

Опубликовано: 29 янв. 2016
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 7.3

Описание

The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.

РелизСтатусПримечание
devel

released

7.47.0-1ubuntu1
esm-infra-legacy/trusty

released

7.35.0-1ubuntu2.6
precise

released

7.22.0-3ubuntu4.15
trusty

released

7.35.0-1ubuntu2.6
trusty/esm

released

7.35.0-1ubuntu2.6
upstream

released

7.47.0
vivid

released

7.38.0-3ubuntu2.3
vivid/stable-phone-overlay

released

7.38.0-3ubuntu2.3
vivid/ubuntu-core

released

7.38.0-3ubuntu2.3
wily

released

7.43.0-1ubuntu2.1

Показывать по

5 Medium

CVSS2

7.3 High

CVSS3

Связанные уязвимости

redhat
около 10 лет назад

The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.

CVSS3: 7.3
nvd
около 10 лет назад

The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.

CVSS3: 7.3
debian
около 10 лет назад

The ConnectionExists function in lib/url.c in libcurl before 7.47.0 do ...

suse-cvrf
почти 10 лет назад

Security update for curl

suse-cvrf
около 10 лет назад

Security update for curl

5 Medium

CVSS2

7.3 High

CVSS3