Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-3620

Опубликовано: 18 нояб. 2014
Источник: debian
EPSS Низкий

Описание

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed7.38.0-1package
curlnot-affectedwheezypackage
curlnot-affectedsqueezepackage

Примечания

  • http://curl.haxx.se/docs/adv_20140910B.html

  • Introduced by https://github.com/bagder/curl/commit/85b9dc8023

EPSS

Процентиль: 90%
0.0424
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.

redhat
почти 12 лет назад

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.

nvd
больше 11 лет назад

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.

github
больше 4 лет назад

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.

EPSS

Процентиль: 90%
0.0424
Низкий