CVE Vulnerabilities

CVE-2014-0138

Improper Authentication

Published: Apr 15, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
CurlHaxx7.10.6 (including)7.10.6 (including)
CurlHaxx7.10.7 (including)7.10.7 (including)
CurlHaxx7.10.8 (including)7.10.8 (including)
CurlHaxx7.11.0 (including)7.11.0 (including)
CurlHaxx7.11.1 (including)7.11.1 (including)
CurlHaxx7.11.2 (including)7.11.2 (including)
CurlHaxx7.12.0 (including)7.12.0 (including)
CurlHaxx7.12.1 (including)7.12.1 (including)
CurlHaxx7.12.2 (including)7.12.2 (including)
CurlHaxx7.12.3 (including)7.12.3 (including)
CurlHaxx7.13.0 (including)7.13.0 (including)
CurlHaxx7.13.1 (including)7.13.1 (including)
CurlHaxx7.13.2 (including)7.13.2 (including)
CurlHaxx7.14.0 (including)7.14.0 (including)
CurlHaxx7.14.1 (including)7.14.1 (including)
CurlHaxx7.15.0 (including)7.15.0 (including)
CurlHaxx7.15.1 (including)7.15.1 (including)
CurlHaxx7.15.2 (including)7.15.2 (including)
CurlHaxx7.15.3 (including)7.15.3 (including)
CurlHaxx7.15.4 (including)7.15.4 (including)
CurlHaxx7.15.5 (including)7.15.5 (including)
CurlHaxx7.16.0 (including)7.16.0 (including)
CurlHaxx7.16.1 (including)7.16.1 (including)
CurlHaxx7.16.2 (including)7.16.2 (including)
CurlHaxx7.16.3 (including)7.16.3 (including)
CurlHaxx7.16.4 (including)7.16.4 (including)
CurlHaxx7.17.0 (including)7.17.0 (including)
CurlHaxx7.17.1 (including)7.17.1 (including)
CurlHaxx7.18.0 (including)7.18.0 (including)
CurlHaxx7.18.1 (including)7.18.1 (including)
CurlHaxx7.18.2 (including)7.18.2 (including)
CurlHaxx7.19.0 (including)7.19.0 (including)
CurlHaxx7.19.1 (including)7.19.1 (including)
CurlHaxx7.19.2 (including)7.19.2 (including)
CurlHaxx7.19.3 (including)7.19.3 (including)
CurlHaxx7.19.4 (including)7.19.4 (including)
CurlHaxx7.19.5 (including)7.19.5 (including)
CurlHaxx7.19.6 (including)7.19.6 (including)
CurlHaxx7.19.7 (including)7.19.7 (including)
CurlHaxx7.20.0 (including)7.20.0 (including)
CurlHaxx7.20.1 (including)7.20.1 (including)
CurlHaxx7.21.0 (including)7.21.0 (including)
CurlHaxx7.21.1 (including)7.21.1 (including)
CurlHaxx7.21.2 (including)7.21.2 (including)
CurlHaxx7.21.3 (including)7.21.3 (including)
CurlHaxx7.21.4 (including)7.21.4 (including)
CurlHaxx7.21.5 (including)7.21.5 (including)
CurlHaxx7.21.6 (including)7.21.6 (including)
CurlHaxx7.21.7 (including)7.21.7 (including)
CurlHaxx7.22.0 (including)7.22.0 (including)
CurlHaxx7.23.0 (including)7.23.0 (including)
CurlHaxx7.23.1 (including)7.23.1 (including)
CurlHaxx7.24.0 (including)7.24.0 (including)
CurlHaxx7.25.0 (including)7.25.0 (including)
CurlHaxx7.26.0 (including)7.26.0 (including)
CurlHaxx7.27.0 (including)7.27.0 (including)
CurlHaxx7.28.0 (including)7.28.0 (including)
CurlHaxx7.28.1 (including)7.28.1 (including)
CurlHaxx7.29.0 (including)7.29.0 (including)
CurlHaxx7.30.0 (including)7.30.0 (including)
CurlHaxx7.31.0 (including)7.31.0 (including)
CurlHaxx7.32.0 (including)7.32.0 (including)
CurlHaxx7.33.0 (including)7.33.0 (including)
CurlHaxx7.34.0 (including)7.34.0 (including)
CurlHaxx7.35.0 (including)7.35.0 (including)
LibcurlHaxx7.10.6 (including)7.10.6 (including)
LibcurlHaxx7.10.7 (including)7.10.7 (including)
LibcurlHaxx7.10.8 (including)7.10.8 (including)
LibcurlHaxx7.11.0 (including)7.11.0 (including)
LibcurlHaxx7.11.1 (including)7.11.1 (including)
LibcurlHaxx7.11.2 (including)7.11.2 (including)
LibcurlHaxx7.12.0 (including)7.12.0 (including)
LibcurlHaxx7.12.1 (including)7.12.1 (including)
LibcurlHaxx7.12.2 (including)7.12.2 (including)
LibcurlHaxx7.12.3 (including)7.12.3 (including)
LibcurlHaxx7.13.0 (including)7.13.0 (including)
LibcurlHaxx7.13.1 (including)7.13.1 (including)
LibcurlHaxx7.13.2 (including)7.13.2 (including)
LibcurlHaxx7.14.0 (including)7.14.0 (including)
LibcurlHaxx7.14.1 (including)7.14.1 (including)
LibcurlHaxx7.15.0 (including)7.15.0 (including)
LibcurlHaxx7.15.1 (including)7.15.1 (including)
LibcurlHaxx7.15.2 (including)7.15.2 (including)
LibcurlHaxx7.15.3 (including)7.15.3 (including)
LibcurlHaxx7.15.4 (including)7.15.4 (including)
LibcurlHaxx7.15.5 (including)7.15.5 (including)
LibcurlHaxx7.16.0 (including)7.16.0 (including)
LibcurlHaxx7.16.1 (including)7.16.1 (including)
LibcurlHaxx7.16.2 (including)7.16.2 (including)
LibcurlHaxx7.16.3 (including)7.16.3 (including)
LibcurlHaxx7.16.4 (including)7.16.4 (including)
LibcurlHaxx7.17.0 (including)7.17.0 (including)
LibcurlHaxx7.17.1 (including)7.17.1 (including)
LibcurlHaxx7.18.0 (including)7.18.0 (including)
LibcurlHaxx7.18.1 (including)7.18.1 (including)
LibcurlHaxx7.18.2 (including)7.18.2 (including)
LibcurlHaxx7.19.0 (including)7.19.0 (including)
LibcurlHaxx7.19.1 (including)7.19.1 (including)
LibcurlHaxx7.19.2 (including)7.19.2 (including)
LibcurlHaxx7.19.3 (including)7.19.3 (including)
LibcurlHaxx7.19.4 (including)7.19.4 (including)
LibcurlHaxx7.19.5 (including)7.19.5 (including)
LibcurlHaxx7.19.6 (including)7.19.6 (including)
LibcurlHaxx7.19.7 (including)7.19.7 (including)
LibcurlHaxx7.20.0 (including)7.20.0 (including)
LibcurlHaxx7.20.1 (including)7.20.1 (including)
LibcurlHaxx7.21.0 (including)7.21.0 (including)
LibcurlHaxx7.21.1 (including)7.21.1 (including)
LibcurlHaxx7.21.2 (including)7.21.2 (including)
LibcurlHaxx7.21.3 (including)7.21.3 (including)
LibcurlHaxx7.21.4 (including)7.21.4 (including)
LibcurlHaxx7.21.5 (including)7.21.5 (including)
LibcurlHaxx7.21.6 (including)7.21.6 (including)
LibcurlHaxx7.21.7 (including)7.21.7 (including)
LibcurlHaxx7.22.0 (including)7.22.0 (including)
LibcurlHaxx7.23.0 (including)7.23.0 (including)
LibcurlHaxx7.23.1 (including)7.23.1 (including)
LibcurlHaxx7.24.0 (including)7.24.0 (including)
LibcurlHaxx7.25.0 (including)7.25.0 (including)
LibcurlHaxx7.26.0 (including)7.26.0 (including)
LibcurlHaxx7.27.0 (including)7.27.0 (including)
LibcurlHaxx7.28.0 (including)7.28.0 (including)
LibcurlHaxx7.28.1 (including)7.28.1 (including)
LibcurlHaxx7.29.0 (including)7.29.0 (including)
LibcurlHaxx7.30.0 (including)7.30.0 (including)
LibcurlHaxx7.31.0 (including)7.31.0 (including)
LibcurlHaxx7.32.0 (including)7.32.0 (including)
LibcurlHaxx7.33.0 (including)7.33.0 (including)
LibcurlHaxx7.34.0 (including)7.34.0 (including)
LibcurlHaxx7.35.0 (including)7.35.0 (including)
Red Hat Enterprise Linux 6RedHatcurl-0:7.19.7-37.el6_5.3*
CurlUbuntudevel*
CurlUbuntulucid*
CurlUbuntuprecise*
CurlUbuntuquantal*
CurlUbuntusaucy*
CurlUbuntuupstream*

Potential Mitigations

References