Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3613

Опубликовано: 18 нояб. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.

РелизСтатусПримечание
devel

released

7.37.1-1ubuntu2
esm-infra-legacy/trusty

released

7.35.0-1ubuntu2.1
lucid

released

7.19.7-1ubuntu1.9
precise

released

7.22.0-3ubuntu4.10
trusty

released

7.35.0-1ubuntu2.1
trusty/esm

released

7.35.0-1ubuntu2.1
upstream

released

7.38.0

Показывать по

EPSS

Процентиль: 82%
0.0182
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.

nvd
почти 11 лет назад

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.

debian
почти 11 лет назад

cURL and libcurl before 7.38.0 does not properly handle IP addresses i ...

github
больше 3 лет назад

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.

oracle-oval
почти 10 лет назад

ELSA-2015-2159: curl security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 82%
0.0182
Низкий

5 Medium

CVSS2