CVE-2014-3613

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
VendorProductVersion
haxxcurl
𝑥
≤ 7.37.1
haxxcurl
7.31.0
haxxcurl
7.32.0
haxxcurl
7.33.0
haxxcurl
7.34.0
haxxcurl
7.35.0
haxxcurl
7.36.0
haxxcurl
7.37.0
haxxlibcurl
𝑥
≤ 7.37.1
haxxlibcurl
7.31.0
haxxlibcurl
7.32.0
haxxlibcurl
7.33.0
haxxlibcurl
7.34.0
haxxlibcurl
7.35.0
haxxlibcurl
7.36.0
haxxlibcurl
7.37.0
applemac_os_x
𝑥
≤ 10.10.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
curl
bullseye
7.74.0-1.3+deb11u13
fixed
bullseye (security)
7.74.0-1.3+deb11u11
fixed
bookworm
7.88.1-10+deb12u7
fixed
bookworm (security)
7.88.1-10+deb12u5
fixed
sid
8.10.1-2
fixed
trixie
8.10.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
curl
trusty
Fixed 7.35.0-1ubuntu2.1
released
precise
Fixed 7.22.0-3ubuntu4.10
released
lucid
Fixed 7.19.7-1ubuntu1.9
released
Common Weakness Enumeration