CVE-2014-0015
curl - information disclosure
EPSS 5.6%
描述
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
如何修補 CVE-2014-0015
要修補 CVE-2014-0015,請將受影響套件升級到下列已修補版本。
- Debian/curl—升級至 7.35.0-1 或更新版本
- Debian/curl—升級至 7.21.0-2.1+squeeze7 或更新版本
CVE-2014-0015 正在被利用嗎?
中等 — EPSS 為 5.6%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 7.35.0-1
- from 0, < 7.21.0-2.1+squeeze7