cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Curl | Haxx | * | 7.37.1 (including) |
Curl | Haxx | 7.31.0 (including) | 7.31.0 (including) |
Curl | Haxx | 7.32.0 (including) | 7.32.0 (including) |
Curl | Haxx | 7.33.0 (including) | 7.33.0 (including) |
Curl | Haxx | 7.34.0 (including) | 7.34.0 (including) |
Curl | Haxx | 7.35.0 (including) | 7.35.0 (including) |
Curl | Haxx | 7.36.0 (including) | 7.36.0 (including) |
Curl | Haxx | 7.37.0 (including) | 7.37.0 (including) |
Curl | Ubuntu | devel | * |
Curl | Ubuntu | trusty | * |
Curl | Ubuntu | upstream | * |