CVE-2015-3148 : Detail

CVE-2015-3148

A01-Broken Access Control
2.95%V3
Network
2015-04-24
12h00 +00:00
2018-01-04
18h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.

CVE Informations

Related Weaknesses

CWE-ID Weakness Name Source
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Metrics

Metrics Score Severity CVSS Vector Source
V2 5 AV:N/AC:L/Au:N/C:N/I:P/A:N [email protected]

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Products Mentioned

Configuraton 0

Fedoraproject>>Fedora >> Version 21

Fedoraproject>>Fedora >> Version 22

Configuraton 0

Canonical>>Ubuntu_linux >> Version 12.04

Canonical>>Ubuntu_linux >> Version 14.04

Canonical>>Ubuntu_linux >> Version 14.10

Canonical>>Ubuntu_linux >> Version 15.04

Debian>>Debian_linux >> Version 7.0

Configuraton 0

Apple>>Mac_os_x >> Version 10.10.0

Apple>>Mac_os_x >> Version 10.10.1

Apple>>Mac_os_x >> Version 10.10.2

Apple>>Mac_os_x >> Version 10.10.3

Apple>>Mac_os_x >> Version 10.10.4

Configuraton 0

Haxx>>Libcurl >> Version 7.10.6

Haxx>>Libcurl >> Version 7.10.7

Haxx>>Libcurl >> Version 7.10.8

Haxx>>Libcurl >> Version 7.11.0

Haxx>>Libcurl >> Version 7.11.1

Haxx>>Libcurl >> Version 7.11.2

Haxx>>Libcurl >> Version 7.12.0

Haxx>>Libcurl >> Version 7.12.1

Haxx>>Libcurl >> Version 7.12.2

Haxx>>Libcurl >> Version 7.12.3

Haxx>>Libcurl >> Version 7.13.0

Haxx>>Libcurl >> Version 7.13.1

Haxx>>Libcurl >> Version 7.13.2

Haxx>>Libcurl >> Version 7.14.0

Haxx>>Libcurl >> Version 7.14.1

Haxx>>Libcurl >> Version 7.15.0

Haxx>>Libcurl >> Version 7.15.1

Haxx>>Libcurl >> Version 7.15.2

Haxx>>Libcurl >> Version 7.15.3

Haxx>>Libcurl >> Version 7.15.4

Haxx>>Libcurl >> Version 7.15.5

Haxx>>Libcurl >> Version 7.16.0

Haxx>>Libcurl >> Version 7.16.1

Haxx>>Libcurl >> Version 7.16.2

Haxx>>Libcurl >> Version 7.16.3

Haxx>>Libcurl >> Version 7.16.4

Haxx>>Libcurl >> Version 7.17.0

Haxx>>Libcurl >> Version 7.17.1

Haxx>>Libcurl >> Version 7.18.0

Haxx>>Libcurl >> Version 7.18.1

Haxx>>Libcurl >> Version 7.18.2

Haxx>>Libcurl >> Version 7.19.0

Haxx>>Libcurl >> Version 7.19.1

Haxx>>Libcurl >> Version 7.19.2

Haxx>>Libcurl >> Version 7.19.3

Haxx>>Libcurl >> Version 7.19.4

Haxx>>Libcurl >> Version 7.19.5

Haxx>>Libcurl >> Version 7.19.6

Haxx>>Libcurl >> Version 7.19.7

Haxx>>Libcurl >> Version 7.20.0

Haxx>>Libcurl >> Version 7.20.1

Haxx>>Libcurl >> Version 7.21.0

Haxx>>Libcurl >> Version 7.21.1

Haxx>>Libcurl >> Version 7.21.2

Haxx>>Libcurl >> Version 7.21.3

Haxx>>Libcurl >> Version 7.21.4

Haxx>>Libcurl >> Version 7.21.5

Haxx>>Libcurl >> Version 7.21.6

Haxx>>Libcurl >> Version 7.21.7

Haxx>>Libcurl >> Version 7.22.0

Haxx>>Libcurl >> Version 7.23.0

Haxx>>Libcurl >> Version 7.23.1

Haxx>>Libcurl >> Version 7.24.0

Haxx>>Libcurl >> Version 7.25.0

Haxx>>Libcurl >> Version 7.26.0

Haxx>>Libcurl >> Version 7.27.0

Haxx>>Libcurl >> Version 7.28.0

Haxx>>Libcurl >> Version 7.28.1

Haxx>>Libcurl >> Version 7.29.0

Haxx>>Libcurl >> Version 7.30.0

Haxx>>Libcurl >> Version 7.31.0

Haxx>>Libcurl >> Version 7.32.0

Haxx>>Libcurl >> Version 7.33.0

Haxx>>Libcurl >> Version 7.34.0

Haxx>>Libcurl >> Version 7.35.0

Haxx>>Libcurl >> Version 7.36.0

Haxx>>Libcurl >> Version 7.37.0

Haxx>>Libcurl >> Version 7.37.1

Haxx>>Libcurl >> Version 7.38.0

Haxx>>Libcurl >> Version 7.39

Haxx>>Libcurl >> Version 7.40.0

Haxx>>Libcurl >> Version 7.41.0

Configuraton 0

Hp>>System_management_homepage >> Version To (including) 7.5.3.1

Configuraton 0

Haxx>>Curl >> Version 7.10.6

Haxx>>Curl >> Version 7.10.7

Haxx>>Curl >> Version 7.10.8

Haxx>>Curl >> Version 7.11.0

Haxx>>Curl >> Version 7.11.1

Haxx>>Curl >> Version 7.11.2

Haxx>>Curl >> Version 7.12.0

Haxx>>Curl >> Version 7.12.1

Haxx>>Curl >> Version 7.12.2

Haxx>>Curl >> Version 7.12.3

Haxx>>Curl >> Version 7.13.0

Haxx>>Curl >> Version 7.13.1

Haxx>>Curl >> Version 7.13.2

Haxx>>Curl >> Version 7.14.0

Haxx>>Curl >> Version 7.14.1

Haxx>>Curl >> Version 7.15.0

Haxx>>Curl >> Version 7.15.1

Haxx>>Curl >> Version 7.15.2

Haxx>>Curl >> Version 7.15.3

Haxx>>Curl >> Version 7.15.4

Haxx>>Curl >> Version 7.15.5

Haxx>>Curl >> Version 7.16.0

Haxx>>Curl >> Version 7.16.1

Haxx>>Curl >> Version 7.16.2

Haxx>>Curl >> Version 7.16.3

Haxx>>Curl >> Version 7.16.4

Haxx>>Curl >> Version 7.17.0

Haxx>>Curl >> Version 7.17.1

Haxx>>Curl >> Version 7.18.0

Haxx>>Curl >> Version 7.18.1

Haxx>>Curl >> Version 7.18.2

Haxx>>Curl >> Version 7.19.0

Haxx>>Curl >> Version 7.19.1

Haxx>>Curl >> Version 7.19.2

Haxx>>Curl >> Version 7.19.3

Haxx>>Curl >> Version 7.19.4

Haxx>>Curl >> Version 7.19.5

Haxx>>Curl >> Version 7.19.6

Haxx>>Curl >> Version 7.19.7

Haxx>>Curl >> Version 7.20.0

Haxx>>Curl >> Version 7.20.1

Haxx>>Curl >> Version 7.21.0

Haxx>>Curl >> Version 7.21.1

Haxx>>Curl >> Version 7.21.2

Haxx>>Curl >> Version 7.21.3

Haxx>>Curl >> Version 7.21.4

Haxx>>Curl >> Version 7.21.5

Haxx>>Curl >> Version 7.21.6

Haxx>>Curl >> Version 7.21.7

Haxx>>Curl >> Version 7.22.0

Haxx>>Curl >> Version 7.23.0

Haxx>>Curl >> Version 7.23.1

Haxx>>Curl >> Version 7.24.0

Haxx>>Curl >> Version 7.25.0

Haxx>>Curl >> Version 7.26.0

Haxx>>Curl >> Version 7.27.0

Haxx>>Curl >> Version 7.28.0

Haxx>>Curl >> Version 7.28.1

Haxx>>Curl >> Version 7.29.0

Haxx>>Curl >> Version 7.30.0

Haxx>>Curl >> Version 7.31.0

Haxx>>Curl >> Version 7.32.0

Haxx>>Curl >> Version 7.33.0

Haxx>>Curl >> Version 7.34.0

Haxx>>Curl >> Version 7.35.0

Haxx>>Curl >> Version 7.36.0

Haxx>>Curl >> Version 7.37.0

Haxx>>Curl >> Version 7.37.1

Haxx>>Curl >> Version 7.38.0

Haxx>>Curl >> Version 7.39.0

Haxx>>Curl >> Version 7.40.0

Haxx>>Curl >> Version 7.41.0

Configuraton 0

Opensuse>>Opensuse >> Version 13.1

Opensuse>>Opensuse >> Version 13.2

References

http://marc.info/?l=bugtraq&m=145612005512270&w=2
Tags : vendor-advisory, x_refsource_HP
http://www.debian.org/security/2015/dsa-3232
Tags : vendor-advisory, x_refsource_DEBIAN
http://www.securityfocus.com/bid/74301
Tags : vdb-entry, x_refsource_BID
http://www.mandriva.com/security/advisories?name=MDVSA-2015:219
Tags : vendor-advisory, x_refsource_MANDRIVA
http://www.ubuntu.com/usn/USN-2591-1
Tags : vendor-advisory, x_refsource_UBUNTU
http://www.securitytracker.com/id/1032232
Tags : vdb-entry, x_refsource_SECTRACK
http://rhn.redhat.com/errata/RHSA-2015-1254.html
Tags : vendor-advisory, x_refsource_REDHAT
http://www.mandriva.com/security/advisories?name=MDVSA-2015:220
Tags : vendor-advisory, x_refsource_MANDRIVA
https://support.apple.com/kb/HT205031
Tags : x_refsource_CONFIRM
https://security.gentoo.org/glsa/201509-02
Tags : vendor-advisory, x_refsource_GENTOO