vulnerability

SUSE: CVE-2016-0755: SUSE Linux Security Advisory

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Jan 29, 2016
Added
Feb 4, 2016
Modified
Feb 4, 2022

Description

The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.

Solutions

suse-upgrade-curlsuse-upgrade-curl-openssl1suse-upgrade-libcurl-develsuse-upgrade-libcurl4suse-upgrade-libcurl4-32bitsuse-upgrade-libcurl4-openssl1suse-upgrade-libcurl4-openssl1-32bitsuse-upgrade-libcurl4-x86suse-upgrade-sles11sp4-docker-image
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.