CVE-2011-2192

Source
https://nvd.nist.gov/vuln/detail/CVE-2011-2192
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2011-2192.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2011-2192
Aliases
Downstream
Published
2011-07-07T21:55:02Z
Modified
2025-08-09T19:01:28Z
Summary
[none]
Details

The Curlinputnegotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

References

Affected packages