cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Curl | Haxx | * | 7.37.1 (including) |
| Curl | Haxx | 7.31.0 (including) | 7.31.0 (including) |
| Curl | Haxx | 7.32.0 (including) | 7.32.0 (including) |
| Curl | Haxx | 7.33.0 (including) | 7.33.0 (including) |
| Curl | Haxx | 7.34.0 (including) | 7.34.0 (including) |
| Curl | Haxx | 7.35.0 (including) | 7.35.0 (including) |
| Curl | Haxx | 7.36.0 (including) | 7.36.0 (including) |
| Curl | Haxx | 7.37.0 (including) | 7.37.0 (including) |
| Curl | Ubuntu | devel | * |
| Curl | Ubuntu | esm-infra-legacy/trusty | * |
| Curl | Ubuntu | trusty | * |
| Curl | Ubuntu | trusty/esm | * |
| Curl | Ubuntu | upstream | * |