Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-8150

Опубликовано: 15 янв. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.

РелизСтатусПримечание
devel

released

7.38.0-3ubuntu2
esm-infra-legacy/trusty

not-affected

7.35.0-1ubuntu2.3
lucid

released

7.19.7-1ubuntu1.11
precise

released

7.22.0-3ubuntu4.12
trusty

released

7.35.0-1ubuntu2.3
trusty/esm

not-affected

7.35.0-1ubuntu2.3
upstream

released

7.38.0-4
utopic

released

7.37.1-1ubuntu3.2

Показывать по

EPSS

Процентиль: 84%
0.0215
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 10 лет назад

CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.

nvd
больше 10 лет назад

CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.

debian
больше 10 лет назад

CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, ...

github
больше 3 лет назад

CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.

oracle-oval
больше 9 лет назад

ELSA-2015-2159: curl security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 84%
0.0215
Низкий

4.3 Medium

CVSS2