[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2014:110 -- Mandriva curl

ID: oval:org.secpod.oval:def:1300314Date: (C)2014-07-24   (M)2022-10-10
Class: PATCHFamily: unix




Updated curl packages fix security vulnerabilities: Paras Sethia discovered that libcurl would sometimes mix up multiple HTTP and HTTPS connections with NTLM authentication to the same server, sending requests for one user over the connection authenticated as a different user . libcurl can in some circumstances re-use the wrong connection when asked to do transfers using other protocols than HTTP and FTP, causing a transfer that was initiated by an application to wrongfully re-use an existing connection to the same server that was authenticated using different credentials . libcurl incorrectly validates wildcard SSL certificates containing literal IP addresses, so under certain conditions, it would allow and use a wildcard match specified in the CN field, allowing a malicious server to participate in a MITM attack or just fool users into believing that it is a legitimate site .

Platform:
Mandriva Enterprise Server 5.2
Product:
curl
Reference:
MDVSA-2014:110
CVE-2014-0015
CVE-2014-0138
CVE-2014-0139
CVE    3
CVE-2014-0139
CVE-2014-0015
CVE-2014-0138
CPE    67
cpe:/a:haxx:curl:7.21.0
cpe:/a:haxx:curl:7.21.3
cpe:/a:haxx:curl:7.23.1
cpe:/a:haxx:curl:7.21.4
...

© SecPod Technologies