cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade curl | Jul 30, 2024 | Jun 22, 2015 |
| Freebsd | — | Upgrade curl | Dec 10, 2025 | Jun 17, 2015 |
| Gentoo Linux | — | Upgrade net-misc/curl. | Oct 30, 2017 | Jun 22, 2015 |
| Mcafee Agent | — | Update McAfee Agent to version 4.8.0.1995Update McAfee Agent to version 5.0.2.132 | Aug 11, 2020 | Jun 22, 2015 |
| Oracle Solaris | — | Upgrade web/curl to version 7.45.0-0.175.3.5.0.4.0 on Solaris 11.3 | May 29, 2017 | Jun 22, 2015 |
| Suse | — | Upgrade libcurl-develUpgrade libcurl4-32bitUpgrade curlUpgrade libcurl4 | Dec 18, 2015 | Jun 22, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub