Lucene search

K
osvGoogleOSV:DLA-211-1
HistoryApr 29, 2015 - 12:00 a.m.

curl - security update

2015-04-2900:00:00
Google
osv.dev
15

0.009 Low

EPSS

Percentile

83.2%

Several vulnerabilities were discovered in cURL, an URL transfer library:

  • CVE-2015-3143
    NTLM-authenticated connections could be wrongly reused for requests
    without any credentials set, leading to HTTP requests being sent
    over the connection authenticated as a different user. This is
    similar to the issue fixed in DSA-2849-1.
  • CVE-2015-3148
    When doing HTTP requests using the Negotiate authentication method
    along with NTLM, the connection used would not be marked as
    authenticated, making it possible to reuse it and send requests for
    one user over the connection authenticated as a different user.