Release date:
Updated on:
Affected Systems:
Daniel Stenberg curl 7.x
RedHat Enterprise Linux
Ubuntu Linux
Unaffected system:
Daniel Stenberg curl 7.21.7
Description:
--------------------------------------------------------------------------------
Bugtraq id: 48434
Cve id: CVE-2011-2192
CURL is a command line FILE transmission tool that supports FTP, FTPS, HTTP, HTTPS, GOPHER, TELNET, DICT, FILE, and LDAP.
CURL/libcURL has a spoofing security vulnerability in the implementation of GSS/Negotiate. Remote attackers can exploit this vulnerability to forge clients on servers using the same GSSAPI mechanism.
Libcurl performs a credential delegate when verifying GSSAPI, and delivers a copy of the Client Security credential to the server. This allows the server to forge other clients using the same GSSAPI mechanism.
<* Source: Richard Silverman
Link: http://curl.haxx.se/docs/adv_20110623.html
Http://support.avaya.com/css/P8/documents/100147330
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Daniel Stenberg
---------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://curl.haxx.se/