FreeBSD : cURL -- inappropriate GSSAPI delegation (9aecb94c-c1ad-11e3-a5ac-001b21614864)
Medium Nessus Plugin ID 73551
SynopsisThe remote FreeBSD host is missing one or more security-related updates.
DescriptioncURL reports :
When doing GSSAPI authentication, libcurl unconditionally performs credential delegation. This hands the server a copy of the client's security credentials, allowing the server to impersonate the client to any other using the same GSSAPI mechanism.
SolutionUpdate the affected packages.