CVE-2016-0755: High severity curl vulnerability
Published Jan 29, 2016
·Updated
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.
Affected Software
6 affected components
haxx curl<=7.46.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
Canonical Ubuntu Linux=15.10
Debian Debian Linux=7.0
Event History
Jan 29, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0755?
CVE-2016-0755 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-0755?
To fix CVE-2016-0755, you should upgrade to libcurl version 7.47.0 or later.
3
Which versions of libcurl are affected by CVE-2016-0755?
Libcurl versions prior to 7.47.0, particularly 7.46.0 and earlier, are affected by CVE-2016-0755.
4
What systems are impacted by CVE-2016-0755?
CVE-2016-0755 impacts various Linux distributions including affected versions of Ubuntu and Debian.
5
What type of attack is CVE-2016-0755 associated with?
CVE-2016-0755 is associated with remote attackers potentially authenticating as other users through improper reuse of NTLM-authenticated proxy connections.