CVE Vulnerabilities

CVE-2015-3143

Published: Apr 24, 2015 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.

Affected Software

Name Vendor Start Version End Version
Curl Haxx 7.10.6 (including) 7.10.6 (including)
Curl Haxx 7.10.7 (including) 7.10.7 (including)
Curl Haxx 7.10.8 (including) 7.10.8 (including)
Curl Haxx 7.11.0 (including) 7.11.0 (including)
Curl Haxx 7.11.1 (including) 7.11.1 (including)
Curl Haxx 7.11.2 (including) 7.11.2 (including)
Curl Haxx 7.12.0 (including) 7.12.0 (including)
Curl Haxx 7.12.1 (including) 7.12.1 (including)
Curl Haxx 7.12.2 (including) 7.12.2 (including)
Curl Haxx 7.12.3 (including) 7.12.3 (including)
Curl Haxx 7.13.0 (including) 7.13.0 (including)
Curl Haxx 7.13.1 (including) 7.13.1 (including)
Curl Haxx 7.13.2 (including) 7.13.2 (including)
Curl Haxx 7.14.0 (including) 7.14.0 (including)
Curl Haxx 7.14.1 (including) 7.14.1 (including)
Curl Haxx 7.15.0 (including) 7.15.0 (including)
Curl Haxx 7.15.1 (including) 7.15.1 (including)
Curl Haxx 7.15.2 (including) 7.15.2 (including)
Curl Haxx 7.15.3 (including) 7.15.3 (including)
Curl Haxx 7.15.4 (including) 7.15.4 (including)
Curl Haxx 7.15.5 (including) 7.15.5 (including)
Curl Haxx 7.16.0 (including) 7.16.0 (including)
Curl Haxx 7.16.1 (including) 7.16.1 (including)
Curl Haxx 7.16.2 (including) 7.16.2 (including)
Curl Haxx 7.16.3 (including) 7.16.3 (including)
Curl Haxx 7.16.4 (including) 7.16.4 (including)
Curl Haxx 7.17.0 (including) 7.17.0 (including)
Curl Haxx 7.17.1 (including) 7.17.1 (including)
Curl Haxx 7.18.0 (including) 7.18.0 (including)
Curl Haxx 7.18.1 (including) 7.18.1 (including)
Curl Haxx 7.18.2 (including) 7.18.2 (including)
Curl Haxx 7.19.0 (including) 7.19.0 (including)
Curl Haxx 7.19.1 (including) 7.19.1 (including)
Curl Haxx 7.19.2 (including) 7.19.2 (including)
Curl Haxx 7.19.3 (including) 7.19.3 (including)
Curl Haxx 7.19.4 (including) 7.19.4 (including)
Curl Haxx 7.19.5 (including) 7.19.5 (including)
Curl Haxx 7.19.6 (including) 7.19.6 (including)
Curl Haxx 7.19.7 (including) 7.19.7 (including)
Curl Haxx 7.20.0 (including) 7.20.0 (including)
Curl Haxx 7.20.1 (including) 7.20.1 (including)
Curl Haxx 7.21.0 (including) 7.21.0 (including)
Curl Haxx 7.21.1 (including) 7.21.1 (including)
Curl Haxx 7.21.2 (including) 7.21.2 (including)
Curl Haxx 7.21.3 (including) 7.21.3 (including)
Curl Haxx 7.21.4 (including) 7.21.4 (including)
Curl Haxx 7.21.5 (including) 7.21.5 (including)
Curl Haxx 7.21.6 (including) 7.21.6 (including)
Curl Haxx 7.21.7 (including) 7.21.7 (including)
Curl Haxx 7.22.0 (including) 7.22.0 (including)
Curl Haxx 7.23.0 (including) 7.23.0 (including)
Curl Haxx 7.23.1 (including) 7.23.1 (including)
Curl Haxx 7.24.0 (including) 7.24.0 (including)
Curl Haxx 7.25.0 (including) 7.25.0 (including)
Curl Haxx 7.26.0 (including) 7.26.0 (including)
Curl Haxx 7.27.0 (including) 7.27.0 (including)
Curl Haxx 7.28.0 (including) 7.28.0 (including)
Curl Haxx 7.28.1 (including) 7.28.1 (including)
Curl Haxx 7.29.0 (including) 7.29.0 (including)
Curl Haxx 7.30.0 (including) 7.30.0 (including)
Curl Haxx 7.31.0 (including) 7.31.0 (including)
Curl Haxx 7.32.0 (including) 7.32.0 (including)
Curl Haxx 7.33.0 (including) 7.33.0 (including)
Curl Haxx 7.34.0 (including) 7.34.0 (including)
Curl Haxx 7.35.0 (including) 7.35.0 (including)
Curl Haxx 7.36.0 (including) 7.36.0 (including)
Curl Haxx 7.37.1 (including) 7.37.1 (including)
Curl Haxx 7.38.0 (including) 7.38.0 (including)
Curl Haxx 7.39.0 (including) 7.39.0 (including)
Curl Haxx 7.40.0 (including) 7.40.0 (including)
Curl Haxx 7.41.0 (including) 7.41.0 (including)
Red Hat Enterprise Linux 6 RedHat curl-0:7.19.7-46.el6 *
Red Hat Enterprise Linux 7 RedHat curl-0:7.29.0-25.el7 *
Curl Ubuntu devel *
Curl Ubuntu lucid *
Curl Ubuntu precise *
Curl Ubuntu trusty *
Curl Ubuntu upstream *
Curl Ubuntu utopic *
Curl Ubuntu vivid *
Curl Ubuntu vivid/stable-phone-overlay *
Curl Ubuntu vivid/ubuntu-core *

References