4.3
CVSSv2

CVE-2011-2192

Published: 07/07/2011 Updated: 27/05/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 up to and including 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

haxx libcurl

apple mac os x

fedoraproject fedora 14

fedoraproject fedora 15

debian debian linux 5.0

debian debian linux 6.0

debian debian linux 7.0

canonical ubuntu linux 8.04

canonical ubuntu linux 10.04

canonical ubuntu linux 10.10

canonical ubuntu linux 11.04

Vendor Advisories

Debian Bug report logs - #631615 CVE-2011-2192: libcurl inappropriate GSSAPI delegation Package: curl; Maintainer for curl is Alessandro Ghedini <ghedo@debianorg>; Source for curl is src:curl (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Sat, 25 Jun 2011 12:27:02 UTC Severity: ser ...
Multiple vulnerabilities in curl ...
Richard Silverman discovered that when doing GSSAPI authentication, libcurl unconditionally performs credential delegation This hands the server a copy of the client's security credentials, allowing the server to impersonate the client to any other using the same GSSAPI mechanism This is obviously a very sensitive operation, which should only be ...