Security Bypass vulnerability in curl - CVE-2015-3143
|ID: oval:org.secpod.oval:def:24538||Date: (C)2015-06-04 (M)2017-10-12|
|Class: VULNERABILITY||Family: unix|
The host is installed with curl 7.29.0 and earlier on Red Hat Enterprise Linux 7 or curl 7.19.7 and earlier on Red Hat Enterprise Linux 6 and is prone to in-correct re-use vulnerability. A flaw is present in the application, which does not properly re-use NTLM connections. Successful exploitation could allow remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
|Red Hat Enterprise Linux 6|
|Red Hat Enterprise Linux 7|