Skip to main content

cURL Information Disclosure Vulnerability

Last Update Date: 4 Feb 2014 16:14 Release Date: 4 Feb 2014 3015 Views

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

A vulnerability has been identified in libcURL, which can be exploited by a remote user to obtain information from the wrong session.

 

When responding to an NTLM-authenticated HTTP or HTTPS request, the system may use the wrong connection (a connection authenticated with different credentials).


Impact

  • Information Disclosure

System / Technologies affected

  • Versions prior to 7.35.0

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (7.35.0).

 


Vulnerability Identifier


Source


Related Link