Back to search
CVE-2014-0015
Published: Feb 2, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
56912
third-party-advisory
x_refsource_SECUNIA
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862
x_refsource_CONFIRM
SSA:2014-044-01
vendor-advisory
x_refsource_SLACKWARE
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
x_refsource_CONFIRM
http://support.apple.com/kb/HT6296
x_refsource_CONFIRM
http://www.vmware.com/security/advisories/VMSA-2014-0012.html
x_refsource_CONFIRM
1029710
vdb-entry
x_refsource_SECTRACK
FEDORA-2014-1876
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2014:0274
vendor-advisory
x_refsource_SUSE
APPLE-SA-2014-06-30-2
vendor-advisory
x_refsource_APPLE
20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
mailing-list
x_refsource_BUGTRAQ
65270
vdb-entry
x_refsource_BID
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
x_refsource_CONFIRM
DSA-2849
vendor-advisory
x_refsource_DEBIAN
59458
third-party-advisory
x_refsource_SECUNIA
20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
mailing-list
x_refsource_FULLDISC
56728
third-party-advisory
x_refsource_SECUNIA
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
x_refsource_CONFIRM
FEDORA-2014-1864
vendor-advisory
x_refsource_FEDORA
59475
third-party-advisory
x_refsource_SECUNIA
http://curl.haxx.se/docs/adv_20140129.html
x_refsource_CONFIRM
USN-2097-1
vendor-advisory
x_refsource_UBUNTU
56734
third-party-advisory
x_refsource_SECUNIA
56731
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now