CURL/libcURL NTLM connection Remote Security Restriction Bypass Vulnerability (CVE-2015-3143)
CURL/libcURL NTLM connection Remote Security Restriction Bypass Vulnerability (CVE-2015-3143)
Release date:
Updated on:
Affected Systems:
CURL 7.10.6-7.41.0
Description:
Bugtraq id: 74299
CVE (CAN) ID: CVE-2015-3143
CURL/libcURL is a command line FILE transmission tool that supports FTP, FTPS, HTTP, HTTPS, GOPHER, TELNET, DICT, FILE, and LDAP.
CURL and libcurl 7.10.6-7.41.0 do not correctly re-use ntlm connections, which allows remote attackers to connect to other identities through unauthenticated requests.
<* Source: Paras Sethia
*>
Suggestion:
Vendor patch:
CURL
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://curl.haxx.se/docs/adv_20150422A.html
Http://www.debian.org/security/2015/dsa-3232
Http://www.ubuntu.com/usn/USN-2591-1
Ubuntu users install the download tool cURL 7.36.0
Linux curl
Sharing of Curl usage and common functions in Unix
Curl command
This article permanently updates the link address: