CVE-2011-2192

Source
https://nvd.nist.gov/vuln/detail/CVE-2011-2192
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2011-2192.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2011-2192
Aliases
Related
Published
2011-07-07T21:55:02Z
Modified
2024-06-30T12:01:22Z
Summary
[none]
Details

The Curlinputnegotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

References

Affected packages

Debian:11 / curl

Package

Name
curl
Purl
pkg:deb/debian/curl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.21.6-2

Ecosystem specific

{
    "urgency": "high"
}

Debian:12 / curl

Package

Name
curl
Purl
pkg:deb/debian/curl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.21.6-2

Ecosystem specific

{
    "urgency": "high"
}

Debian:13 / curl

Package

Name
curl
Purl
pkg:deb/debian/curl?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.21.6-2

Ecosystem specific

{
    "urgency": "high"
}