Security Bypass vulnerability in curl - CVE-2015-3148
|ID: oval:org.secpod.oval:def:24537||Date: (C)2015-06-04 (M)2017-10-12|
|Class: VULNERABILITY||Family: unix|
The host is installed with curl 7.29.0 and earlier on Red Hat Enterprise Linux 7 or curl 7.19.7 and earlier on Red Hat Enterprise Linux 6 and is prone to in-correct re-use vulnerability. A flaw is present in the application, which does not properly re-use authenticated negotiate connections. Successful exploitation could allow remote attackers to connect as other users via a request.
|Red Hat Enterprise Linux 6|
|Red Hat Enterprise Linux 7|