CVE-2014-3620
18.11.2014, 15:59
cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| haxx | curl | 𝑥 ≤ 7.37.1 |
| haxx | curl | 7.31.0 |
| haxx | curl | 7.32.0 |
| haxx | curl | 7.33.0 |
| haxx | curl | 7.34.0 |
| haxx | curl | 7.35.0 |
| haxx | curl | 7.36.0 |
| haxx | curl | 7.37.0 |
| haxx | libcurl | 𝑥 ≤ 7.37.1 |
| haxx | libcurl | 7.31.0 |
| haxx | libcurl | 7.32.0 |
| haxx | libcurl | 7.33.0 |
| haxx | libcurl | 7.34.0 |
| haxx | libcurl | 7.35.0 |
| haxx | libcurl | 7.36.0 |
| haxx | libcurl | 7.37.0 |
| apple | mac_os_x | 𝑥 ≤ 10.10.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| curl |
| ||||||||||||||||
| libcurl-devel |
| ||||||||||||||||
| libcurl4 |
| ||||||||||||||||
| libcurl4-32bit |
|
Common Weakness Enumeration
References