CVE-2014-0015
CVE-2014-0015
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://archives.neohapsis.com/archives/bugtraq/2014-06/0172.htmlhttp://curl.haxx.se/docs/adv_20140129.htmlhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127627.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/128408.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00066.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/56728http://secunia.com/advisories/56731http://secunia.com/advisories/56734http://secunia.com/advisories/56912http://secunia.com/advisories/59458