CVE-2016-0755 describes a vulnerability in libcurl versions prior to 7.47.0, specifically within the ConnectionExists function in lib/url.c, affecting products like canonical curl, Debian curl, and haxx curl. This flaw prevents proper re-use of NTLM-authenticated proxy connections, potentially allowing remote attackers to authenticate as other users. With a CVSS v3 score of 7.3 (HIGH), this vulnerability has a network attack vector, low attack complexity, and could lead to low impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.46.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
15.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:* | ||
15.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
curl: NTLM credentials not-checked for proxy connection re-use
Jan 27, 2016NTLM credentials not-checked for proxy connection reuse
Jan 27, 2016NTLM credentials not-checked for proxy connection reuse
Jan 27, 2016