CVE Vulnerabilities

CVE-2014-3620

Published: Nov 18, 2014 | Modified: May 11, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.

Affected Software

Name Vendor Start Version End Version
Curl Haxx * 7.37.1 (including)
Curl Haxx 7.31.0 (including) 7.31.0 (including)
Curl Haxx 7.32.0 (including) 7.32.0 (including)
Curl Haxx 7.33.0 (including) 7.33.0 (including)
Curl Haxx 7.34.0 (including) 7.34.0 (including)
Curl Haxx 7.35.0 (including) 7.35.0 (including)
Curl Haxx 7.36.0 (including) 7.36.0 (including)
Curl Haxx 7.37.0 (including) 7.37.0 (including)
Curl Ubuntu devel *
Curl Ubuntu trusty *
Curl Ubuntu upstream *

References