|
|
Log in / Subscribe / Register

curl: authentication bypass

Package(s):curl CVE #(s):CVE-2016-0755
Created:January 27, 2016 Updated:February 17, 2016
Description: From the Debian advisory:

Isaac Boukris discovered that cURL, an URL transfer library, reused NTLM-authenticated proxy connections without properly making sure that the connection was authenticated with the same credentials as set for the new transfer. This could lead to HTTP requests being sent over the connection authenticated as a different user.

Alerts:
Gentoo 201701-47 curl 2017-01-19
Fedora FEDORA-2016-3fa315a5dd curl 2016-02-02
Arch Linux ASA-201602-4 lib32-curl 2016-02-02
Arch Linux ASA-201602-3 curl 2016-02-02
Fedora FEDORA-2016-57bebab3b6 curl 2016-01-30
Ubuntu USN-2882-1 curl 2016-01-27
Debian DSA-3455-1 curl 2016-01-27
SUSE SUSE-SU-2016:0778-1 sles11sp4-docker-image 2016-03-15
Fedora FEDORA-2016-5a141de5d9 mingw-curl 2016-02-17
Fedora FEDORA-2016-55137a3adb mingw-curl 2016-02-17
Slackware SSA:2016-039-01 curl 2016-02-08
openSUSE openSUSE-SU-2016:0376-1 curl 2016-02-08
openSUSE openSUSE-SU-2016:0373-1 curl 2016-02-07
openSUSE openSUSE-SU-2016:0360-1 curl 2016-02-07
Mageia MGASA-2016-0050 curl 2016-02-05

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds