The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Curl | Haxx | * | 7.46.0 (including) |
Curl | Ubuntu | devel | * |
Curl | Ubuntu | precise | * |
Curl | Ubuntu | trusty | * |
Curl | Ubuntu | upstream | * |
Curl | Ubuntu | vivid | * |
Curl | Ubuntu | vivid/stable-phone-overlay | * |
Curl | Ubuntu | vivid/ubuntu-core | * |
Curl | Ubuntu | wily | * |