VDB

DEBIAN-CVE-2011-2192

DEBIAN-CVE-2011-2192 PUBLISHED

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

Affected Products

VendorProductVersions
Debian:12curl0, 0, 0
Debian:14curl0, 0, 0
Debian:13curl0, 0, 0
Debian:11curl0, 0, 0

Timeline

  • Jul 7, 2011 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›