CVE-2014-0015
Publication date 31 January 2014
Last updated 24 July 2024
Ubuntu priority
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
Status
Package | Ubuntu Release | Status |
---|---|---|
curl | 13.10 saucy |
Fixed 7.32.0-1ubuntu1.3
|
12.10 quantal |
Fixed 7.27.0-1ubuntu1.8
|
|
12.04 LTS precise |
Fixed 7.22.0-3ubuntu4.7
|
|
10.04 LTS lucid |
Fixed 7.19.7-1ubuntu1.6
|
Patch details
Package | Patch details |
---|---|
curl |
|
References
Related Ubuntu Security Notices (USN)
- USN-2097-1
- curl vulnerability
- 3 February 2014