CVE Vulnerabilities

CVE-2014-8150

Published: Jan 15, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.

Affected Software

NameVendorStart VersionEnd Version
Debian_linuxDebian7.0 (including)7.0 (including)
Red Hat Enterprise Linux 6RedHatcurl-0:7.19.7-46.el6*
Red Hat Enterprise Linux 7RedHatcurl-0:7.29.0-25.el7*
CurlUbuntudevel*
CurlUbuntuesm-infra-legacy/trusty*
CurlUbuntulucid*
CurlUbuntuprecise*
CurlUbuntutrusty*
CurlUbuntutrusty/esm*
CurlUbuntuupstream*
CurlUbuntuutopic*

References