CVE-2014-3613
curl: incorrect handling of IP addresses in cookie domain
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
cURL y libcurl anteriores a 7.38.0 no manejan correctamente las direcciones IP en nombres de dominio de cookies, lo que permite a atacantes remotos usar cookies definidas por ellos mismos o enviar cookies arbitrarias a ciertos sitios, como originada por un sitio en 192.168.0.1 estableciendo las cookies para un sitio en 127.168.0.1.
It was found that the libcurl library did not correctly handle partial literal IP addresses when parsing received HTTP cookies. An attacker able to trick a user into connecting to a malicious server could use this flaw to set the user's cookie to a crafted domain, making other cookie-related issues easier to exploit.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-05-14 CVE Reserved
- 2014-09-11 CVE Published
- 2024-06-30 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
- CWE-310: Cryptographic Issues
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743 | X_refsource_confirm | |
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html | X_refsource_confirm | |
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html | X_refsource_confirm | |
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html | X_refsource_confirm | |
http://www.securityfocus.com/bid/69748 | Vdb Entry | |
https://support.apple.com/kb/HT205031 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://curl.haxx.se/docs/adv_20140910A.html | 2018-01-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | <= 7.37.1 Search vendor "Haxx" for product "Curl" and version " <= 7.37.1" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | 7.31.0 Search vendor "Haxx" for product "Curl" and version "7.31.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | 7.32.0 Search vendor "Haxx" for product "Curl" and version "7.32.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | 7.33.0 Search vendor "Haxx" for product "Curl" and version "7.33.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | 7.34.0 Search vendor "Haxx" for product "Curl" and version "7.34.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | 7.35.0 Search vendor "Haxx" for product "Curl" and version "7.35.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | 7.36.0 Search vendor "Haxx" for product "Curl" and version "7.36.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | 7.37.0 Search vendor "Haxx" for product "Curl" and version "7.37.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | <= 7.37.1 Search vendor "Haxx" for product "Libcurl" and version " <= 7.37.1" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | 7.31.0 Search vendor "Haxx" for product "Libcurl" and version "7.31.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | 7.32.0 Search vendor "Haxx" for product "Libcurl" and version "7.32.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | 7.33.0 Search vendor "Haxx" for product "Libcurl" and version "7.33.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | 7.34.0 Search vendor "Haxx" for product "Libcurl" and version "7.34.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | 7.35.0 Search vendor "Haxx" for product "Libcurl" and version "7.35.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | 7.36.0 Search vendor "Haxx" for product "Libcurl" and version "7.36.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | 7.37.0 Search vendor "Haxx" for product "Libcurl" and version "7.37.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | <= 10.10.4 Search vendor "Apple" for product "Mac Os X" and version " <= 10.10.4" | - |
Affected
|