CVE-2014-0015
published 2014-02-02CVE-2014-0015: cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent…
PriorityP419medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
1.27%
79.9th percentile
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
Affected
180 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.9.5 | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | curl | < curl 7.36.0-1 (bookworm) | curl 7.36.0-1 (bookworm) |
| debian | curl | < curl 7.35.0-1 (bookworm) | curl 7.35.0-1 (bookworm) |
| debian | curl | < curl 7.47.0-1 (bookworm) | curl 7.47.0-1 (bookworm) |
| debian | curl | < curl 7.42.0-1 (bookworm) | curl 7.42.0-1 (bookworm) |
| debian | debian_linux | — | — |
| haxx | curl | <= 7.46.0 | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
curl: NTLM credentials not-checked for proxy connection re-use
vendor_redhat·2016-01-27·CVSS 4.0
CVE-2016-0755 [MEDIUM] CWE-287 curl: NTLM credentials not-checked for proxy connection re-use
curl: NTLM credentials not-checked for proxy connection re-use
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.
Package: curl (Red Hat Enterprise Linux 5) - Will not fix
Package: curl (Red Hat Enterprise Linux 6) - Will not fix
Package: curl (Red Hat Enterprise Linux 7) - Will not fix
Package: curl (Red Hat JBoss Enterprise Web Server 3) - Will not fix
Package: httpd24-curl (Red Hat Software Collections) - Not affected
Debian
CVE-2016-0755: curl - The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not pro...
vendor_debian·2016·CVSS 4.0
CVE-2016-0755 [MEDIUM] CVE-2016-0755: curl - The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not pro...
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.
Scope: local
bookworm: resolved (fixed in 7.47.0-1)
bullseye: resolved (fixed in 7.47.0-1)
forky: resolved (fixed in 7.47.0-1)
sid: resolved (fixed in 7.47.0-1)
trixie: resolved (fixed in 7.47.0-1)
Red Hat
curl: re-using authenticated connection when unauthenticated
vendor_redhat·2015-04-22·CVSS 4.0
CVE-2015-3143 [MEDIUM] CWE-287 curl: re-using authenticated connection when unauthenticated
curl: re-using authenticated connection when unauthenticated
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
It was discovered that libcurl could incorrectly reuse NTLM-authenticated connections for subsequent unauthenticated requests to the same host. If an application using libcurl established an NTLM-authenticated connection to a server, and sent subsequent unauthenticated requests to the same server, the unauthenticated requests could be sent over the NTLM-authenticated connection, appearing as if they were sent by the NTLM authenticated user.
Statement: This issue affects the version of curl package as shipped with Red Hat Enter
Debian
CVE-2015-3143: curl - cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections...
vendor_debian·2015·CVSS 4.0
CVE-2015-3143 [MEDIUM] CVE-2015-3143: curl - cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections...
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
Scope: local
bookworm: resolved (fixed in 7.42.0-1)
bullseye: resolved (fixed in 7.42.0-1)
forky: resolved (fixed in 7.42.0-1)
sid: resolved (fixed in 7.42.0-1)
trixie: resolved (fixed in 7.42.0-1)
VMware
VMware vSphere product updates address security vulnerabilities
vendor_vmware·2014-12-04·CVSS 4.3
CVE-2013-1752 [MEDIUM] VMware vSphere product updates address security vulnerabilities
VMSA-2014-0012: VMware vSphere product updates address security vulnerabilities
a. VMware vCSA cross-site scripting vulnerability VMware vCenter Server Appliance (vCSA) contains a vulnerability that may allow for Cross Site Scripting. Exploitation of this vulnerability in vCenter Server requires tricking a user to click on a malicious link or to open a malicious web page. VMware would like to thank Tanya Secker of Trustwave SpiderLabs for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-3797 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with/ Apply Patch VMware Pro
Red Hat
curl: wrong re-use of connections in libcurl
vendor_redhat·2014-03-26·CVSS 4.0
CVE-2014-0138 [MEDIUM] curl: wrong re-use of connections in libcurl
curl: wrong re-use of connections in libcurl
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
Statement: This issue affects the version of curl as shipped with Red Hat Enterprise Linux 5 and 7. The Red Hat Security Response Team has rated this issue as having Moderate security impact, a future update may address this flaw.
Package: curl (Red Hat Enterprise Linux 5) - Will not fix
Package: curl (Red Hat Enterprise Linux 7) - Not affected
Ubuntu
curl vulnerability
vendor_ubuntu·2014-02-03
CVE-2014-0015 curl vulnerability
Title: curl vulnerability
Summary: libcurl could be made to expose sensitive information.
Paras Sethia and Yehezkel Horowitz discovered that libcurl incorrectly
reused connections when NTLM authentication was being used. This could lead
to the use of unintended credentials, possibly exposing sensitive
information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
curl: re-use of wrong HTTP NTLM connection in libcurl
vendor_redhat·2014-01-29·CVSS 4.0
CVE-2014-0015 [MEDIUM] curl: re-use of wrong HTTP NTLM connection in libcurl
curl: re-use of wrong HTTP NTLM connection in libcurl
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
Statement: This issue affects the version of curl as shipped with Red Hat Enterprise Linux 5 and 7. The Red Hat Security Response Team has rated this issue as having Moderate security impact, a future update may address this flaw.
Mitigation: Avoid using HTTP NTLM in your application. If you must use NTLM authentication, ensure that it is the only requested authentication method (use --ntlm specifically, do not use --anyauth or other authentication methods).
Package: curl (Red Hat Enterprise Linux 5) - Will not fix
Package:
Debian
CVE-2014-0138: curl - The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) S...
vendor_debian·2014·CVSS 4.0
CVE-2014-0138 [MEDIUM] CVE-2014-0138: curl - The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) S...
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
Scope: local
bookworm: resolved (fixed in 7.36.0-1)
bullseye: resolved (fixed in 7.36.0-1)
forky: resolved (fixed in 7.36.0-1)
sid: resolved (fixed in 7.36.0-1)
trixie: resolved (fixed in 7.36.0-1)
Debian
CVE-2014-0015: curl - cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method...
vendor_debian·2014·CVSS 4.0
CVE-2014-0015 [MEDIUM] CVE-2014-0015: curl - cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method...
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
Scope: local
bookworm: resolved (fixed in 7.35.0-1)
bullseye: resolved (fixed in 7.35.0-1)
forky: resolved (fixed in 7.35.0-1)
sid: resolved (fixed in 7.35.0-1)
trixie: resolved (fixed in 7.35.0-1)
GHSA
GHSA-93wp-ggwv-r77q: cURL and libcurl 7
ghsa_unreviewed·2022-05-14
CVE-2014-0015 [MEDIUM] CWE-287 GHSA-93wp-ggwv-r77q: cURL and libcurl 7
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
GHSA
GHSA-j832-g86m-353x: The default configuration in cURL and libcurl 7
ghsa_unreviewed·2022-05-14·CVSS 4.0
CVE-2014-0138 [MEDIUM] CWE-287 GHSA-j832-g86m-353x: The default configuration in cURL and libcurl 7
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
GHSA
GHSA-ff7q-9j5g-56pg: The ConnectionExists function in lib/url
ghsa_unreviewed·2022-05-14·CVSS 4.0
CVE-2016-0755 [MEDIUM] CWE-287 GHSA-ff7q-9j5g-56pg: The ConnectionExists function in lib/url
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.
GHSA
GHSA-6mxf-77w3-cj5m: cURL and libcurl 7
ghsa_unreviewed·2022-05-14·CVSS 4.0
CVE-2015-3143 [MEDIUM] GHSA-6mxf-77w3-cj5m: cURL and libcurl 7
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
OSV
CVE-2016-0755: The ConnectionExists function in lib/url
osv·2016-01-29·CVSS 4.0
CVE-2016-0755 [MEDIUM] CVE-2016-0755: The ConnectionExists function in lib/url
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.
OSV
CVE-2015-3143: cURL and libcurl 7
osv·2015-04-24·CVSS 4.0
CVE-2015-3143 [MEDIUM] CVE-2015-3143: cURL and libcurl 7
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
OSV
CVE-2014-0138: The default configuration in cURL and libcurl 7
osv·2014-04-15·CVSS 4.0
CVE-2014-0138 [MEDIUM] CVE-2014-0138: The default configuration in cURL and libcurl 7
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
OSV
CVE-2014-0015: cURL and libcurl 7
osv·2014-02-02·CVSS 4.0
CVE-2014-0015 [MEDIUM] CVE-2014-0015: cURL and libcurl 7
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0213 CVE-2014-0214 CVE-2014-0215 CVE-2014-0216 CVE-2014-0217 CVE-2014-0218 moodle: upstream 2.7, 2.6.3, 2.5.6, and 2.4.10 security fixes
bugzilla·2014-05-21·CVSS 6.8
CVE-2014-0213 [MEDIUM] CVE-2014-0213 CVE-2014-0214 CVE-2014-0215 CVE-2014-0216 CVE-2014-0217 CVE-2014-0218 moodle: upstream 2.7, 2.6.3, 2.5.6, and 2.4.10 security fixes
CVE-2014-0213 CVE-2014-0214 CVE-2014-0215 CVE-2014-0216 CVE-2014-0217 CVE-2014-0218 moodle: upstream 2.7, 2.6.3, 2.5.6, and 2.4.10 security fixes
Moodle upstream has released versions 2.7, 2.6.3, 2.5.6, and 2.4.10 to fix the following security flaws:
CVE-2014-0213 MSA-14-0014: Cross-site request forgery possible in Assignment
CVE-2014-0214 MSA-14-0015: Web service token expiry issue for MoodleMobile
CVE-2014-0215 MSA-14-0016: Anonymous student identity revealed in assignment
CVE-2014-0216 MSA-14-0017: File access issue in HTML block
CVE-2014-0217 MSA-14-0018: Information leak in courses
CVE-2014-0218 MSA-14-0019: Reflected XSS in URL downloader repository
For a full summary and patch links, refer to the following:
http://seclists.org/oss-sec/2014/q2/329
Discussion:
Created moodle tra
Bugzilla
CVE-2014-0138 curl: wrong re-use of connections in libcurl
bugzilla·2014-03-21·CVSS 4.0
CVE-2014-0138 [MEDIUM] CVE-2014-0138 curl: wrong re-use of connections in libcurl
CVE-2014-0138 curl: wrong re-use of connections in libcurl
Daniel Stenberg reported the following vulnerability in cURL:
libcurl can in some circumstances re-use the wrong connection when asked to
do transfers using other protocols than HTTP and FTP.
libcurl features a pool of recent connections so that subsequent requests
can re-use an existing connection to avoid overhead.
When re-using a connection a range of criterion must first be met. Due to an
error in the code, a transfer that was initiated by an application could
wrongfully re-use an existing connection to the same server that was
authenticated using different credentials. The existing logic basically only
worked well enough for HTTP and FTP, while all other network protocols were
silently, but erroneously, assumed to work lik
Bugzilla
CVE-2014-0015 curl: re-use of wrong HTTP NTLM connection in libcurl [fedora-all]
bugzilla·2014-01-29·CVSS 4.0
CVE-2014-0015 [MEDIUM] CVE-2014-0015 curl: re-use of wrong HTTP NTLM connection in libcurl [fedora-all]
CVE-2014-0015 curl: re-use of wrong HTTP NTLM connection in libcurl [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue
Bugzilla
CVE-2014-0015 curl: re-use of wrong HTTP NTLM connection in libcurl
bugzilla·2014-01-15·CVSS 4.0
CVE-2014-0015 [MEDIUM] CVE-2014-0015 curl: re-use of wrong HTTP NTLM connection in libcurl
CVE-2014-0015 curl: re-use of wrong HTTP NTLM connection in libcurl
Daniel Stenberg reported the following vulnerability in cURL:
libcurl can in some circumstances re-use the wrong connection when asked to
do an NTLM-authenticated HTTP or HTTPS request.
libcurl features a pool of recent connections so that subsequent requests
can re-use an existing connection to avoid overhead.
When re-using a connection a range of criterion must first be met. Due to a
logical error in the code, a request that was issued by an application could
wrongfully re-use an existing connection to the same server that was
authenticated using different credentials. One underlying reason being that
NTLM authenticates connections and not requests, contrary to how HTTP is
designed to work and how other authenticatio
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://archives.neohapsis.com/archives/bugtraq/2014-06/0172.htmlhttp://curl.haxx.se/docs/adv_20140129.htmlhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127627.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/128408.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00066.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/56728http://secunia.com/advisories/56731http://secunia.com/advisories/56734http://secunia.com/advisories/56912http://secunia.com/advisories/59458http://secunia.com/advisories/59475http://support.apple.com/kb/HT6296http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862http://www.debian.org/security/2014/dsa-2849http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/65270http://www.securitytracker.com/id/1029710http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.502652http://www.ubuntu.com/usn/USN-2097-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-06/0172.htmlhttp://curl.haxx.se/docs/adv_20140129.htmlhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127627.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/128408.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00066.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/56728http://secunia.com/advisories/56731http://secunia.com/advisories/56734http://secunia.com/advisories/56912http://secunia.com/advisories/59458http://secunia.com/advisories/59475http://support.apple.com/kb/HT6296http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862http://www.debian.org/security/2014/dsa-2849http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/65270http://www.securitytracker.com/id/1029710http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.502652http://www.ubuntu.com/usn/USN-2097-1http://www.vmware.com/security/advisories/VMSA-2014-0012.html
2014-02-02
Published