4.3

CVE-2011-2192

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

Data is provided by the National Vulnerability Database (NVD)
HaxxLibcurl Version >= 7.10.6 <= 7.21.6
ApplemacOS X Version < 10.7.3
FedoraprojectFedora Version14
FedoraprojectFedora Version15
DebianDebian Linux Version5.0
DebianDebian Linux Version6.0
DebianDebian Linux Version7.0
CanonicalUbuntu Linux Version8.04 SwEditionlts
CanonicalUbuntu Linux Version10.04 SwEditionlts
CanonicalUbuntu Linux Version10.10
CanonicalUbuntu Linux Version11.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.51% 0.794
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
http://www.securitytracker.com/id?1025713
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=711454
Third Party Advisory
Issue Tracking