Total vulnerabilities in the database
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.
Software | From | Fixed in |
---|---|---|
haxx / curl | - | 7.46.0.x |
canonical / ubuntu_linux | 12.04 | 12.04.x |
debian / debian_linux | 7.0 | 7.0.x |
canonical / ubuntu_linux | 15.10 | 15.10.x |
canonical / ubuntu_linux | 14.04 | 14.04.x |
canonical / ubuntu_linux | 15.04 | 15.04.x |