Unrated severityNVD Advisory· Published Jun 22, 2015· Updated May 6, 2026
CVE-2015-3236
CVE-2015-3236
Description
cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors.
Affected products
8Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlnvdPatchThird Party Advisory
- www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlnvdPatchThird Party Advisory
- curl.haxx.se/docs/adv_20150617A.htmlnvdVendor Advisory
- www.securityfocus.com/bid/91787nvdThird Party AdvisoryVDB Entry
- lists.fedoraproject.org/pipermail/package-announce/2015-June/160660.htmlnvd
- www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlnvd
- www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlnvd
- www.securityfocus.com/bid/75385nvd
- kc.mcafee.com/corporate/indexnvd
- security.gentoo.org/glsa/201509-02nvd
News mentions
0No linked articles in our index yet.