DSA-2849-1 curl -- information disclosure

Related Vulnerabilities: CVE-2014-0015  

Paras Sethia discovered that libcurl, a client-side URL transfer library, would sometimes mix up multiple HTTP and HTTPS connections with NTLM authentication to the same server, sending requests for one user over the connection authenticated as a different user. For the oldstable distribution (squeeze), this problem has been fixed in version 7.21.0-2.1+squeeze7. For the stable distribution (wheezy), this problem has been fixed in version 7.26.0-1+wheezy8. For the unstable distribution (sid), this problem has been fixed in version 7.35.0-1. We recommend that you upgrade your curl packages.

Debian Security Advisory

DSA-2849-1 curl -- information disclosure

Date Reported:
31 Jan 2014
Affected Packages:
curl
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2014-0015.
More information:

Paras Sethia discovered that libcurl, a client-side URL transfer library, would sometimes mix up multiple HTTP and HTTPS connections with NTLM authentication to the same server, sending requests for one user over the connection authenticated as a different user.

For the oldstable distribution (squeeze), this problem has been fixed in version 7.21.0-2.1+squeeze7.

For the stable distribution (wheezy), this problem has been fixed in version 7.26.0-1+wheezy8.

For the unstable distribution (sid), this problem has been fixed in version 7.35.0-1.

We recommend that you upgrade your curl packages.