Advisories ยป MGASA-2016-0050

Updated curl packages fix security vulnerability

Publication date: 05 Feb 2016
Modification date: 05 Feb 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-0755

Description

libcurl before 7.47.0 will reuse NTLM-authenticated proxy connections
without properly making sure that the connection was authenticated with
the same credentials as set for this transfer. The effect of this flaw is
that the application could be reusing a proxy connection using the
previously used credentials and thus it could be given to or prevented
access from resources that it wasn't intended to (CVE-2016-0755).
                

References

SRPMS

5/core