PT-2015-6074 · Canonical+9 · Ubuntu+10

Paras Sethia

·

Published

2015-04-22

·

Updated

2024-06-15

·

CVE-2015-3143

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions cURL and libcurl versions 7.10.6 through 7.41.0 libcurl (affected versions not specified) in apple mac os x, canonical ubuntu linux, debian debian linux, hp system management homepage
Description The issue is related to the improper re-use of NTLM connections, allowing remote attackers to connect as other users via an unauthenticated request. This is similar to a previously known issue.
Recommendations For cURL and libcurl versions 7.10.6 through 7.41.0: update to a version that properly handles NTLM connections to prevent unauthorized access. For libcurl in apple mac os x, canonical ubuntu linux, debian debian linux, hp system management homepage: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1396
CESA-2015_1254
CESA-2015_2159
CVE-2015-3143
DLA-211-1
DSA-3232-1
MGASA-2015-0179
OPENSUSE-SU-2024:10303-1
RHSA-2015:1254
RHSA-2015:2159
RHSA-2015_1254
RHSA-2015_2159
SUSE-SU-2015:0962-1
SUSE-SU-2015:0990-1
SUSE-SU-2015_0962-1
SUSE-SU-2015_0990-1
USN-2591-1

Affected Products

Alt Linux
Centos
Debian
Junos
Red Hat
Suse
Hp System Management Homepage
Ubuntu
Curl
Libcurl
Apple Macos