First published: Thu Aug 23 2018(Updated: )
curl 7.x before 7.10.7 sends CONNECT proxy credentials to the remote server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Curl | >=7.1.0<7.10.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1605 is classified as a moderate severity vulnerability.
To fix CVE-2003-1605, upgrade curl to version 7.10.7 or later.
The main issue of CVE-2003-1605 is that curl versions 7.x prior to 7.10.7 incorrectly send CONNECT proxy credentials to the remote server.
CVE-2003-1605 affects curl versions 7.1.0 up to, but not including, 7.10.7.
Curl is a command-line tool and library for transferring data using various network protocols.