Mandriva Linux Security Advisory : curl (MDVSA-2015:220)

Medium Nessus Plugin ID 83244


The remote Mandriva Linux host is missing one or more security updates.


Updated curl packages fix security vulnerabilities :

NTLM-authenticated connections could be wrongly reused for requests without any credentials set, leading to HTTP requests being sent over the connection authenticated as a different user (CVE-2015-3143).

When doing HTTP requests using the Negotiate authentication method along with NTLM, the connection used would not be marked as authenticated, making it possible to reuse it and send requests for one user over the connection authenticated as a different user (CVE-2015-3148).


Update the affected packages.

See Also

Plugin Details

Severity: Medium

ID: 83244

File Name: mandriva_MDVSA-2015-220.nasl

Version: $Revision: 2.1 $

Type: local

Published: 2015/05/05

Modified: 2015/05/05

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 5

Temporal Score: 4.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:curl, p-cpe:/a:mandriva:linux:curl-examples, p-cpe:/a:mandriva:linux:lib64curl-devel, p-cpe:/a:mandriva:linux:lib64curl4, cpe:/o:mandriva:business_server:1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2015/05/04

Reference Information

CVE: CVE-2015-3143, CVE-2015-3148

BID: 74299, 74301

MDVSA: 2015:220