First published: Mon Jun 22 2015(Updated: )
cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
curl | =7.40.0 | |
curl | =7.41.0 | |
curl | =7.42.0 | |
curl | =7.42.1 | |
Haxx Libcurl | =7.40.0 | |
Haxx Libcurl | =7.41.0 | |
Haxx Libcurl | =7.42.0 | |
Haxx Libcurl | =7.42.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.