|
|
Log in / Subscribe / Register

Mageia alert MGASA-2016-0050 (curl)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2016-0050: Updated curl packages fix security vulnerability
Date:  Fri, 5 Feb 2016 18:26:51 +0100
Message-ID:  <20160205172651.AB8F821BE3B@valstar.mageia.org>

MGASA-2016-0050 - Updated curl packages fix security vulnerability Publication date: 05 Feb 2016 URL: http://advisories.mageia.org/MGASA-2016-0050.html Type: security Affected Mageia releases: 5 CVE: CVE-2016-0755 Description: libcurl before 7.47.0 will reuse NTLM-authenticated proxy connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. The effect of this flaw is that the application could be reusing a proxy connection using the previously used credentials and thus it could be given to or prevented access from resources that it wasn't intended to (CVE-2016-0755). References: - https://bugs.mageia.org/show_bug.cgi?id=17629 - http://curl.haxx.se/docs/adv_20160127A.html - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0755 SRPMS: - 5/core/curl-7.40.0-3.3.mga5


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds