Описание
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services". libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needed | |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra-legacy/xenial | needed | |
| esm-infra/bionic | needed | |
| esm-infra/focal | needed | |
| jammy | needed | |
| noble | needed | |
| questing | needed | |
| resolute | needed | |
| upstream | pending | 8.21.0 |
Показывать по
10
EPSS
Процентиль: 24%
0.00315
Низкий
Связанные уязвимости
EPSS
Процентиль: 24%
0.00315
Низкий