Vulnerability Description
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Haxx | Curl | <= 7.37.1 |
| Haxx | Libcurl | <= 7.37.1 |
| Apple | Mac Os X | <= 10.10.4 |
Related Weaknesses (CWE)
References
- http://curl.haxx.se/docs/adv_20140910A.htmlPatch
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00024.html
- http://rhn.redhat.com/errata/RHSA-2015-1254.html
- http://www.debian.org/security/2014/dsa-3022Vendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.h
- http://www.securityfocus.com/bid/69748
- https://support.apple.com/kb/HT205031
- http://curl.haxx.se/docs/adv_20140910A.htmlPatch
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00024.html
FAQ
What is CVE-2014-3613?
CVE-2014-3613 is a vulnerability with a CVSS score of 5.0 (MEDIUM). cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrate...
How severe is CVE-2014-3613?
CVE-2014-3613 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3613?
Check the references section above for vendor advisories and patch information. Affected products include: Haxx Curl, Haxx Libcurl, Apple Mac Os X.