Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3613

Опубликовано: 10 сент. 2014
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.

It was found that the libcurl library did not correctly handle partial literal IP addresses when parsing received HTTP cookies. An attacker able to trick a user into connecting to a malicious server could use this flaw to set the user's cookie to a crafted domain, making other cookie-related issues easier to exploit.

Отчет

This issue affects the versions of curl as shipped with Red Hat Enterprise Linux 5 and is not planned to be corrected in future updates. Inktank Ceph Enterprise 1.1 and 1.2 receives only qualified Important and Critical impact security fixes. This issue has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Inktank Ceph Enterprise Support Matrix: http://www.inktank.com/enterprise/support/

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5curlWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerAffected
Red Hat JBoss Enterprise Web Server 1ice-1.1Will not fix
Red Hat JBoss Enterprise Web Server 1ice-1.2Will not fix
Red Hat Enterprise Linux 6curlFixedRHSA-2015:125420.07.2015
Red Hat Enterprise Linux 7curlFixedRHSA-2015:215919.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1136154curl: incorrect handling of IP addresses in cookie domain

EPSS

Процентиль: 82%
0.0182
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.

nvd
почти 11 лет назад

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.

debian
почти 11 лет назад

cURL and libcurl before 7.38.0 does not properly handle IP addresses i ...

github
больше 3 лет назад

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.

oracle-oval
почти 10 лет назад

ELSA-2015-2159: curl security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 82%
0.0182
Низкий

4.3 Medium

CVSS2

Уязвимость CVE-2014-3613