4
CVSSv2

CVE-2014-0015

Published: 02/02/2014 Updated: 09/10/2018
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
VMScore: 356
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

cURL and libcurl 7.10.6 up to and including 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent malicious users to authenticate as other users via a request.

Vulnerable Product Search on Vulmon Subscribe to Product

haxx libcurl 7.30.0

haxx libcurl 7.28.1

haxx libcurl 7.29.0

haxx libcurl 7.25.0

haxx libcurl 7.26.0

haxx libcurl 7.21.5

haxx libcurl 7.19.0

haxx libcurl 7.19.7

haxx libcurl 7.18.0

haxx libcurl 7.16.2

haxx libcurl 7.16.3

haxx libcurl 7.14.0

haxx libcurl 7.14.1

haxx libcurl 7.12.3

haxx libcurl 7.11.0

haxx libcurl 7.27.0

haxx libcurl 7.28.0

haxx libcurl 7.23.1

haxx libcurl 7.24.0

haxx libcurl 7.21.2

haxx libcurl 7.21.3

haxx libcurl 7.21.4

haxx libcurl 7.19.5

haxx libcurl 7.19.6

haxx libcurl 7.16.0

haxx libcurl 7.16.1

haxx libcurl 7.15.3

haxx libcurl 7.15.4

haxx libcurl 7.15.5

haxx libcurl 7.12.1

haxx libcurl 7.12.2

haxx libcurl 7.10.8

haxx libcurl 7.31.0

haxx libcurl 7.32.0

haxx libcurl 7.21.6

haxx libcurl 7.21.7

haxx libcurl 7.20.0

haxx libcurl 7.20.1

haxx libcurl 7.19.1

haxx libcurl 7.19.2

haxx libcurl 7.18.1

haxx libcurl 7.18.2

haxx libcurl 7.16.4

haxx libcurl 7.15.0

haxx libcurl 7.13.0

haxx libcurl 7.13.1

haxx libcurl 7.11.1

haxx libcurl 7.11.2

haxx libcurl 7.33.0

haxx libcurl 7.34.0

haxx libcurl 7.22.0

haxx libcurl 7.23.0

haxx libcurl 7.21.0

haxx libcurl 7.21.1

haxx libcurl 7.19.3

haxx libcurl 7.19.4

haxx libcurl 7.17.0

haxx libcurl 7.17.1

haxx libcurl 7.15.1

haxx libcurl 7.15.2

haxx libcurl 7.13.2

haxx libcurl 7.12.0

haxx libcurl 7.10.6

haxx libcurl 7.10.7

haxx curl 7.30.0

haxx curl 7.31.0

haxx curl 7.21.1

haxx curl 7.21.0

haxx curl 7.21.7

haxx curl 7.22.0

haxx curl 7.28.1

haxx curl 7.29.0

haxx curl 7.19.6

haxx curl 7.19.7

haxx curl 7.16.1

haxx curl 7.16.2

haxx curl 7.16.3

haxx curl 7.15.5

haxx curl 7.14.0

haxx curl 7.12.2

haxx curl 7.12.3

haxx curl 7.32.0

haxx curl 7.21.2

haxx curl 7.21.5

haxx curl 7.21.6

haxx curl 7.27.0

haxx curl 7.28.0

haxx curl 7.19.4

haxx curl 7.19.5

haxx curl 7.17.1

haxx curl 7.16.0

haxx curl 7.15.3

haxx curl 7.15.4

haxx curl 7.12.0

haxx curl 7.12.1

haxx curl 7.10.7

haxx curl 7.10.8

haxx curl 7.21.3

haxx curl 7.21.4

haxx curl 7.25.0

haxx curl 7.26.0

haxx curl 7.19.2

haxx curl 7.19.3

haxx curl 7.18.2

haxx curl 7.17.0

haxx curl 7.15.1

haxx curl 7.15.2

haxx curl 7.13.1

haxx curl 7.13.2

haxx curl 7.11.2

haxx curl 7.10.6

haxx curl 7.33.0

haxx curl 7.34.0

haxx curl 7.20.1

haxx curl 7.20.0

haxx curl 7.23.0

haxx curl 7.23.1

haxx curl 7.24.0

haxx curl 7.19.0

haxx curl 7.19.1

haxx curl 7.18.0

haxx curl 7.18.1

haxx curl 7.16.4

haxx curl 7.15.0

haxx curl 7.14.1

haxx curl 7.13.0

haxx curl 7.11.0

haxx curl 7.11.1

Vendor Advisories

libcurl could be made to expose sensitive information ...
Paras Sethia discovered that libcurl, a client-side URL transfer library, would sometimes mix up multiple HTTP and HTTPS connections with NTLM authentication to the same server, sending requests for one user over the connection authenticated as a different user For the oldstable distribution (squeeze), this problem has been fixed in version 7210 ...
cURL and libcurl 7106 through 7340, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request ...
cURL and libcurl 7106 through 7340, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request ...