Mageia alert MGASA-2016-0050 (curl)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2016-0050: Updated curl packages fix security vulnerability | |
| Date: | Fri, 5 Feb 2016 18:26:51 +0100 | |
| Message-ID: | <20160205172651.AB8F821BE3B@valstar.mageia.org> |
MGASA-2016-0050 - Updated curl packages fix security vulnerability Publication date: 05 Feb 2016 URL: http://advisories.mageia.org/MGASA-2016-0050.html Type: security Affected Mageia releases: 5 CVE: CVE-2016-0755 Description: libcurl before 7.47.0 will reuse NTLM-authenticated proxy connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. The effect of this flaw is that the application could be reusing a proxy connection using the previously used credentials and thus it could be given to or prevented access from resources that it wasn't intended to (CVE-2016-0755). References: - https://bugs.mageia.org/show_bug.cgi?id=17629 - http://curl.haxx.se/docs/adv_20160127A.html - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0755 SRPMS: - 5/core/curl-7.40.0-3.3.mga5
