PT-2015-6074 · Canonical+9 · Ubuntu+10

Paras Sethia

·

Publicado

2015-04-22

·

Atualizado

2024-06-15

·

CVE-2015-3143

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions cURL and libcurl versions 7.10.6 through 7.41.0 libcurl (affected versions not specified) in apple mac os x, canonical ubuntu linux, debian debian linux, hp system management homepage
Description The issue is related to the improper re-use of NTLM connections, allowing remote attackers to connect as other users via an unauthenticated request. This is similar to a previously known issue.
Recommendations For cURL and libcurl versions 7.10.6 through 7.41.0: update to a version that properly handles NTLM connections to prevent unauthorized access. For libcurl in apple mac os x, canonical ubuntu linux, debian debian linux, hp system management homepage: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1396
CESA-2015_1254
CESA-2015_2159
CVE-2015-3143
DLA-211-1
DSA-3232-1
MGASA-2015-0179
OPENSUSE-SU-2024:10303-1
RHSA-2015:1254
RHSA-2015:2159
RHSA-2015_1254
RHSA-2015_2159
SUSE-SU-2015:0962-1
SUSE-SU-2015:0990-1
SUSE-SU-2015_0962-1
SUSE-SU-2015_0990-1
USN-2591-1

Produtos afetados

Alt Linux
Centos
Debian
Junos
Red Hat
Suse
Hp System Management Homepage
Ubuntu
Curl
Libcurl
Apple Macos