cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-64-1 | curl security update |
Debian DSA |
DSA-3022-1 | curl security update |
EUVD |
EUVD-2014-3577 | cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1. |
Ubuntu USN |
USN-2346-1 | curl vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T10:50:17.964Z
Reserved: 2014-05-14T00:00:00
Link: CVE-2014-3613
No data.
Status : Deferred
Published: 2014-11-18T15:59:00.140
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-3613
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN