CVE-2017-2628: Critical severity curl vulnerability
curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVEGSSAPI define was meanwhile substituted by USEHTTPNEGOTIATE. This issue was introduced in RHEL 6.7 and affects RHEL 6 curl only.
Other sources
It was found that the fix for CVE-2015-3148 did not correctly backported to curl in RHEL 6 because it did not reflect the fact that the HAVEGSSAPI define was meanwhile substituted by USEHTTPNEGOTIATE.
The original issue was described as:
It was discovered that libcurl could incorrectly reuse Negotiate authenticated HTTP connections for subsequent requests. If an application using libcurl established a Negotiate authenticated HTTP connection to a server and sent subsequent requests with different credentials, the connection could be re-used with the initial set of credentials instead of using the new ones.
This issue was introduced in RHEL 6.7 and affects RHEL 6 curl only.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2628?
CVE-2017-2628 has a medium severity rating due to its potential impact on the security of affected systems.
How do I fix CVE-2017-2628?
To fix CVE-2017-2628, upgrade curl to version 7.19.7-53 or later on Red Hat Enterprise Linux 6.
Which versions of curl are affected by CVE-2017-2628?
CVE-2017-2628 affects curl versions shipped in Red Hat Enterprise Linux 6 before 7.19.7-53.
When was the issue that led to CVE-2017-2628 introduced?
The issue leading to CVE-2017-2628 was introduced in RHEL 6.7.
What systems are impacted by CVE-2017-2628?
CVE-2017-2628 impacts Red Hat Enterprise Linux 6, including Desktop, Server, and Workstation variants.