|
|
| |
|
| |
curl: exposed client credentials
| Package(s): | curl |
CVE #(s): | CVE-2011-2192
|
| Created: | June 24, 2011 |
Updated: | March 6, 2012 |
| Description: |
From the Ubuntu advisory:
Richard Silverman discovered that when doing GSSAPI authentication,
libcurl unconditionally performs credential delegation, handing the
server a copy of the client's security credential. |
| Alerts: |
|
( Log in to post comments)
|
|
|