CVE-2015-3236

Description

cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
4.525

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2015-3236,CVE-2015-3237 are affected in Curl For Windows 7.42.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.40.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.41.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.42.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.42.1Windows
Vulnerabilities CVE-2015-3237,CVE-2015-3236 are fixed in Curl For Windows 7.43.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234