Warning message

This translation is outdated. For the most up-to-date information, please refer to the English version.

CVE-2017-2628

Impact:
Moderate
Public Date:
2017-03-29
CWE:
CWE-287
Bugzilla:
1422464: CVE-2017-2628 curl: negotiate not treated as connection-oriented (incomplete fix for CVE-2015-3148)
It was found that the fix for CVE-2015-3148 in curl was incomplete. An application using libcurl with HTTP Negotiate authentication could incorrectly re-use credentials for subsequent requests to the same server.

Find out more about CVE-2017-2628 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 4.8
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact Low
Availability Impact None

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 6 (curl) RHSA-2017:0847 2017-03-29

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 7 curl Not affected
Red Hat Enterprise Linux 5 curl Not affected
Red Hat Ceph Storage 2 curl Not affected
RHEV Manager 3 mingw-virt-viewer Not affected

Acknowledgements

This issue was discovered by Paulo Andrade (Red Hat).

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.