The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2271-1 | curl security update |
EUVD |
EUVD-2011-2183 | The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests. |
Ubuntu USN |
USN-1158-1 | curl vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T22:53:17.373Z
Reserved: 2011-05-31T00:00:00
Link: CVE-2011-2192
No data.
Status : Deferred
Published: 2011-07-07T21:55:02.320
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-2192
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN