LWN.net Logo

curl: exposed client credentials

Package(s):curl CVE #(s):CVE-2011-2192
Created:June 24, 2011 Updated:March 6, 2012
Description: From the Ubuntu advisory:

Richard Silverman discovered that when doing GSSAPI authentication, libcurl unconditionally performs credential delegation, handing the server a copy of the client's security credential.

Alerts:
CentOS CESA-2011:0918 2011-08-14
Mandriva MDVSA-2011:116 2011-07-22
CentOS CESA-2011:0918 2011-07-06
Scientific Linux SL-curl-20110705 2011-07-05
Red Hat RHSA-2011:0918-01 2011-07-05
Fedora FEDORA-2011-8640 2011-06-24
Debian DSA-2271-1 2011-07-02
Fedora FEDORA-2011-8586 2011-06-24
Ubuntu USN-1158-1 2011-06-24
openSUSE openSUSE-SU-2012:0199-1 2012-02-09
Gentoo 201203-02 2012-03-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds