DSA-3455-1 curl -- security update

Related Vulnerabilities: CVE-2016-0755  

Isaac Boukris discovered that cURL, an URL transfer library, reused NTLM-authenticated proxy connections without properly making sure that the connection was authenticated with the same credentials as set for the new transfer. This could lead to HTTP requests being sent over the connection authenticated as a different user. For the stable distribution (jessie), this problem has been fixed in version 7.38.0-4+deb8u3. For the unstable distribution (sid), this problem has been fixed in version 7.47.0-1. We recommend that you upgrade your curl packages.

Debian Security Advisory

DSA-3455-1 curl -- security update

Date Reported:
27 Jan 2016
Affected Packages:
curl
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-0755.
More information:

Isaac Boukris discovered that cURL, an URL transfer library, reused NTLM-authenticated proxy connections without properly making sure that the connection was authenticated with the same credentials as set for the new transfer. This could lead to HTTP requests being sent over the connection authenticated as a different user.

For the stable distribution (jessie), this problem has been fixed in version 7.38.0-4+deb8u3.

For the unstable distribution (sid), this problem has been fixed in version 7.47.0-1.

We recommend that you upgrade your curl packages.