ALAS-2016-652

Related Vulnerabilities: CVE-2016-0755  

The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015. (CVE-2016-0755)

ALAS-2016-652


Amazon Linux AMI Security Advisory: ALAS-2016-652
Advisory Release Date: 2016-02-09 13:30 Pacific
Advisory Updated Date: 2016-02-09 13:30 Pacific
Severity: Low
References: CVE-2016-0755 

Issue Overview:

The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015. (CVE-2016-0755)


Affected Packages:

curl


Issue Correction:
Run yum update curl to update your system.

New Packages:
i686:
    libcurl-devel-7.40.0-8.54.amzn1.i686
    curl-7.40.0-8.54.amzn1.i686
    curl-debuginfo-7.40.0-8.54.amzn1.i686
    libcurl-7.40.0-8.54.amzn1.i686

src:
    curl-7.40.0-8.54.amzn1.src

x86_64:
    libcurl-devel-7.40.0-8.54.amzn1.x86_64
    libcurl-7.40.0-8.54.amzn1.x86_64
    curl-debuginfo-7.40.0-8.54.amzn1.x86_64
    curl-7.40.0-8.54.amzn1.x86_64