Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-3620

Опубликовано: 18 нояб. 2014
Источник: debian

Описание

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed7.38.0-1package
curlnot-affectedwheezypackage
curlnot-affectedsqueezepackage

Примечания

  • http://curl.haxx.se/docs/adv_20140910B.html

  • Introduced by https://github.com/bagder/curl/commit/85b9dc8023

Связанные уязвимости

ubuntu
около 11 лет назад

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.

redhat
больше 11 лет назад

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.

nvd
около 11 лет назад

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.

github
больше 3 лет назад

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.