Get a Pentest and security assessment of your IT network.

News

libcurl has had authentication leak bug dated back to before September 1999

According to a security advisory, libcurl is affected by a couple of issues, one of them might cause the leakage of authentication data to third parties. The problem is related to the way it handles custom headers in HTTP requests. The second issue, CVE-2018-1000007, is described as an HTTP/2 trailer out-of-bounds read vulnerability tracked as CVE-2019-100, the patch was published on GitHub. Affected versions are libcURL 7.1 to and including 7.57.0, later versions (7.58.0) are not affected.”]

Source: http://securityaffairs.co/wordpress/68205/hacking/libcurl-authentication-leak-bug.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Thousands of Magento websites compromised to serve malware

News

Facebook Bug #4: Password Reset Vulnerability Found in www.facebook.com