CVE-2015-3236: Infoleak
cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curleasyreset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3236?
CVE-2015-3236 is considered to have a medium severity due to its potential to expose sensitive HTTP Basic authentication credentials.
How do I fix CVE-2015-3236?
To fix CVE-2015-3236, upgrade cURL and libcurl to version 7.43.0 or later, which includes the security patches.
What versions are affected by CVE-2015-3236?
CVE-2015-3236 affects cURL and libcurl versions 7.40.0 through 7.42.1 inclusive.
What can attackers do with CVE-2015-3236?
Attackers can exploit CVE-2015-3236 to potentially obtain HTTP Basic authentication credentials from previous connections.
Does CVE-2015-3236 apply to both cURL and libcurl?
Yes, CVE-2015-3236 affects both cURL and libcurl versions listed in the vulnerability details.