VulnerabilityModified
CVE-2011-2192
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI…
MEDIUM 4.3EPSS 2.88%
Does this matter?
Lower severity and a low EPSS score (2.88%). Track it; it rarely justifies an emergency change on its own.
Description
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 2.88% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- haxx/libcurl · apple/mac os x · fedoraproject/fedora · debian/debian linux · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- http://curl.haxx.se/curl-gssapi-delegation.patchBroken Link
- http://curl.haxx.se/docs/adv_20110623.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062287.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061992.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/45047Third Party Advisory
- http://secunia.com/advisories/45067Third Party Advisory
- http://secunia.com/advisories/45088Third Party Advisory
- http://secunia.com/advisories/45144Third Party Advisory
- http://secunia.com/advisories/45181Third Party Advisory
- http://secunia.com/advisories/48256Third Party Advisory
- http://security.gentoo.org/glsa/glsa-201203-02.xmlThird Party Advisory
- http://support.apple.com/kb/HT5130Third Party Advisory
- http://www.debian.org/security/2011/dsa-2271Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:116Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0918.htmlThird Party Advisory
- http://www.securitytracker.com/id?1025713Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1158-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=711454Issue Tracking, Third Party Advisory
- http://curl.haxx.se/curl-gssapi-delegation.patchBroken Link
- http://curl.haxx.se/docs/adv_20110623.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062287.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061992.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/45047Third Party Advisory
- http://secunia.com/advisories/45067Third Party Advisory
- http://secunia.com/advisories/45088Third Party Advisory
- http://secunia.com/advisories/45144Third Party Advisory
- http://secunia.com/advisories/45181Third Party Advisory
- http://secunia.com/advisories/48256Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.