The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 01:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://curl.haxx.se/docs/adv_20130412.html - Vendor Advisory | |
References | () http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102056.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102711.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2013-May/104207.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2013-May/104598.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105539.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106606.html - | |
References | () http://lists.opensuse.org/opensuse-updates/2013-06/msg00013.html - | |
References | () http://lists.opensuse.org/opensuse-updates/2013-06/msg00016.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0771.html - | |
References | () http://secunia.com/advisories/53044 - Vendor Advisory | |
References | () http://secunia.com/advisories/53051 - Vendor Advisory | |
References | () http://secunia.com/advisories/53097 - Vendor Advisory | |
References | () http://www.debian.org/security/2012/dsa-2660 - | |
References | () http://www.mandriva.com/security/advisories?name=MDVSA-2013:151 - | |
References | () http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html - | |
References | () http://www.osvdb.org/92316 - | |
References | () http://www.securityfocus.com/bid/59058 - | |
References | () http://www.ubuntu.com/usn/USN-1801-1 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=950577 - | |
References | () https://github.com/bagder/curl/commit/2eb8dcf26cb37f09cffe26909a646e702dbcab66 - | |
References | () https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0121 - |
Information
Published : 2013-04-29 22:55
Updated : 2024-11-21 01:50
NVD link : CVE-2013-1944
Mitre link : CVE-2013-1944
CVE.ORG link : CVE-2013-1944
JSON object : View
Products Affected
haxx
- curl
- libcurl
canonical
- ubuntu_linux
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor