]> granicus.if.org Git - curl/commit
http: do not leak basic auth credentials on re-used connections
authorKamil Dudka <kdudka@redhat.com>
Thu, 28 May 2015 18:04:35 +0000 (20:04 +0200)
committerDaniel Stenberg <daniel@haxx.se>
Wed, 17 Jun 2015 05:43:13 +0000 (07:43 +0200)
commit24a8359b256f8a3d7892f21f156a4bf0a42710d5
tree7490da5df95227837ff2adbc272a4e2efffd696a
parent24f0b6ebf7c4411ac9d82a6269d4c136856a1166
http: do not leak basic auth credentials on re-used connections

CVE-2015-3236

This partially reverts commit curl-7_39_0-237-g87c4abb

Reported-by: Tomas Tomecek, Kamil Dudka
Bug: http://curl.haxx.se/docs/adv_20150617A.html
lib/http.c