CVE-2016-8615
01.08.2018, 06:29
A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie jar.
Vendor | Product | Version |
---|---|---|
haxx | curl | 𝑥 < 7.51.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References