curl: information disclosure
Package(s): | curl | CVE #(s): | CVE-2014-0015 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Created: | January 31, 2014 | Updated: | February 24, 2014 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description: | From the Debian advisory: Paras Sethia discovered that libcurl, a client-side URL transfer library, would sometimes mix up multiple HTTP and HTTPS connections with NTLM authentication to the same server, sending requests for one user over the connection authenticated as a different user. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Alerts: |
|