The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
21 Nov 2024, 02:28
Type | Values Removed | Values Added |
---|---|---|
References | () http://curl.haxx.se/docs/adv_20150429.html - Vendor Advisory | |
References | () http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743 - | |
References | () http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-updates/2015-05/msg00017.html - | |
References | () http://www.debian.org/security/2015/dsa-3240 - Third Party Advisory | |
References | () http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html - | |
References | () http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html - | |
References | () http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html - Patch, Third Party Advisory | |
References | () http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html - Patch, Third Party Advisory | |
References | () http://www.securityfocus.com/bid/74408 - | |
References | () http://www.securitytracker.com/id/1032233 - Third Party Advisory, VDB Entry | |
References | () http://www.ubuntu.com/usn/USN-2591-1 - Third Party Advisory | |
References | () https://kc.mcafee.com/corporate/index?page=content&id=SB10131 - | |
References | () https://support.apple.com/kb/HT205031 - Third Party Advisory |
Information
Published : 2015-05-01 15:59
Updated : 2024-11-21 02:28
NVD link : CVE-2015-3153
Mitre link : CVE-2015-3153
CVE.ORG link : CVE-2015-3153
JSON object : View
Products Affected
apple
- mac_os_x
oracle
- enterprise_manager_ops_center
haxx
- curl
- libcurl
canonical
- ubuntu_linux
debian
- debian_linux
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor