Updated curl packages fix security vulnerability
Publication date: 05 Feb 2016Modification date: 05 Feb 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-0755
Description
libcurl before 7.47.0 will reuse NTLM-authenticated proxy connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. The effect of this flaw is that the application could be reusing a proxy connection using the previously used credentials and thus it could be given to or prevented access from resources that it wasn't intended to (CVE-2016-0755).
References
SRPMS
5/core
- curl-7.40.0-3.3.mga5