Описание
A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie jar.
Релиз | Статус | Примечание |
---|---|---|
devel | released | 7.50.1-1ubuntu2 |
esm-infra-legacy/trusty | not-affected | 7.35.0-1ubuntu2.10 |
esm-infra/xenial | not-affected | 7.47.0-1ubuntu2.2 |
precise | released | 7.22.0-3ubuntu4.17 |
precise/esm | not-affected | 7.22.0-3ubuntu4.17 |
trusty | released | 7.35.0-1ubuntu2.10 |
trusty/esm | not-affected | 7.35.0-1ubuntu2.10 |
upstream | released | 7.51.0 |
vivid/stable-phone-overlay | ignored | end of life |
vivid/ubuntu-core | released | 7.38.0-3ubuntu2.4 |
Показывать по
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3
Связанные уязвимости
A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie jar.
A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie jar.
A flaw was found in curl before version 7.51. If cookie state is writt ...
A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie jar.
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3