CVE-2014-3620
Mandriva Linux Security Advisory 2014-187
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.
cURL y libcurl anteriores a 7.38.0 permite a atacantes remotos evadir Same Origin Policy y configurar cookies para sitios arbitrarios mediante la configuraciĆ³n de una cookie de un dominio de nivel superior.
Paras Sethia discovered that libcurl would sometimes mix up multiple HTTP and HTTPS connections with NTLM authentication to the same server, sending requests for one user over the connection authenticated as a different user. libcurl can in some circumstances re-use the wrong connection when asked to do transfers using other protocols than HTTP and FTP, causing a transfer that was initiated by an application to wrongfully re-use an existing connection to the same server that was authenticated using different credentials. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-05-14 CVE Reserved
- 2014-09-11 CVE Published
- 2024-08-06 CVE Updated
- 2025-04-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743 | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2022/05/11/2 | Mailing List |
|
http://www.securityfocus.com/bid/69742 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://curl.haxx.se/docs/adv_20140910B.html | 2022-05-11 |
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html | 2022-05-11 | |
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00024.html | 2022-05-11 | |
http://www.debian.org/security/2014/dsa-3022 | 2022-05-11 | |
https://support.apple.com/kb/HT205031 | 2022-05-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | <= 7.37.1 Search vendor "Haxx" for product "Curl" and version " <= 7.37.1" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | 7.31.0 Search vendor "Haxx" for product "Curl" and version "7.31.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | 7.32.0 Search vendor "Haxx" for product "Curl" and version "7.32.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | 7.33.0 Search vendor "Haxx" for product "Curl" and version "7.33.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | 7.34.0 Search vendor "Haxx" for product "Curl" and version "7.34.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | 7.35.0 Search vendor "Haxx" for product "Curl" and version "7.35.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | 7.36.0 Search vendor "Haxx" for product "Curl" and version "7.36.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | 7.37.0 Search vendor "Haxx" for product "Curl" and version "7.37.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | <= 7.37.1 Search vendor "Haxx" for product "Libcurl" and version " <= 7.37.1" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | 7.31.0 Search vendor "Haxx" for product "Libcurl" and version "7.31.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | 7.32.0 Search vendor "Haxx" for product "Libcurl" and version "7.32.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | 7.33.0 Search vendor "Haxx" for product "Libcurl" and version "7.33.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | 7.34.0 Search vendor "Haxx" for product "Libcurl" and version "7.34.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | 7.35.0 Search vendor "Haxx" for product "Libcurl" and version "7.35.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | 7.36.0 Search vendor "Haxx" for product "Libcurl" and version "7.36.0" | - |
Affected
| ||||||
Haxx Search vendor "Haxx" | Libcurl Search vendor "Haxx" for product "Libcurl" | 7.37.0 Search vendor "Haxx" for product "Libcurl" and version "7.37.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | <= 10.10.4 Search vendor "Apple" for product "Mac Os X" and version " <= 10.10.4" | - |
Affected
|