[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3455-1 curl -- curl

ID: oval:org.secpod.oval:def:602348Date: (C)2016-02-01   (M)2022-09-22
Class: PATCHFamily: unix




Isaac Boukris discovered that cURL, an URL transfer library, reused NTLM-authenticated proxy connections without properly making sure that the connection was authenticated with the same credentials as set for the new transfer. This could lead to HTTP requests being sent over the connection authenticated as a different user.

Platform:
Debian 8.x
Product:
curl
Reference:
DSA-3455-1
CVE-2016-0755
CVE    1
CVE-2016-0755
CPE    2
cpe:/a:haxx:curl
cpe:/o:debian:debian_linux:8.x

© SecPod Technologies