Back to search
CVE-2011-2192
Published: Jul 7, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
MDVSA-2011:116
vendor-advisory
x_refsource_MANDRIVA
45181
third-party-advisory
x_refsource_SECUNIA
http://support.apple.com/kb/HT5130
x_refsource_CONFIRM
45144
third-party-advisory
x_refsource_SECUNIA
USN-1158-1
vendor-advisory
x_refsource_UBUNTU
http://curl.haxx.se/docs/adv_20110623.html
x_refsource_CONFIRM
45067
third-party-advisory
x_refsource_SECUNIA
FEDORA-2011-8640
vendor-advisory
x_refsource_FEDORA
1025713
vdb-entry
x_refsource_SECTRACK
RHSA-2011:0918
vendor-advisory
x_refsource_REDHAT
APPLE-SA-2012-02-01-1
vendor-advisory
x_refsource_APPLE
GLSA-201203-02
vendor-advisory
x_refsource_GENTOO
48256
third-party-advisory
x_refsource_SECUNIA
DSA-2271
vendor-advisory
x_refsource_DEBIAN
https://bugzilla.redhat.com/show_bug.cgi?id=711454
x_refsource_CONFIRM
http://curl.haxx.se/curl-gssapi-delegation.patch
x_refsource_CONFIRM
45088
third-party-advisory
x_refsource_SECUNIA
FEDORA-2011-8586
vendor-advisory
x_refsource_FEDORA
45047
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now