CVE Database
/

CVE-2011-2192

Back to search

CVE-2011-2192

Published: Jul 7, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

VendorProductVersions

n/a

n/a

affected
n/a

References

MDVSA-2011:116
vendor-advisory
x_refsource_MANDRIVA
45181
third-party-advisory
x_refsource_SECUNIA
45144
third-party-advisory
x_refsource_SECUNIA
USN-1158-1
vendor-advisory
x_refsource_UBUNTU
45067
third-party-advisory
x_refsource_SECUNIA
FEDORA-2011-8640
vendor-advisory
x_refsource_FEDORA
1025713
vdb-entry
x_refsource_SECTRACK
RHSA-2011:0918
vendor-advisory
x_refsource_REDHAT
APPLE-SA-2012-02-01-1
vendor-advisory
x_refsource_APPLE
GLSA-201203-02
vendor-advisory
x_refsource_GENTOO
48256
third-party-advisory
x_refsource_SECUNIA
DSA-2271
vendor-advisory
x_refsource_DEBIAN
45088
third-party-advisory
x_refsource_SECUNIA
FEDORA-2011-8586
vendor-advisory
x_refsource_FEDORA
45047
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now