secure keyword for https://targethttp://target (same
hostname, but using clear text HTTP) using the same cookie setpath=/,).
Since this site is not secure, the cookie should just be ignored.The bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path.
The presumed and correct behavior would be to plainly ignore the second set of the cookie since it was already set as secure on a secure host so overriding it on an insecure host should not be okay.
The product reads data past the end, or before the beginning, of the intended buffer.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Curl | Haxx | 8.13.0 (including) | 8.16.0 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | curl-0:8.12.1-2.el10_1.2 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | curl-0:8.12.1-1.el10_0.4 | * |
| Red Hat Enterprise Linux 8 | RedHat | curl-0:7.61.1-34.el8_10.9 | * |
| Red Hat Enterprise Linux 9 | RedHat | curl-0:7.76.1-35.el9_7.3 | * |
| Red Hat Enterprise Linux 9 | RedHat | curl-0:7.76.1-35.el9_7.3 | * |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | curl-0:7.76.1-14.el9_0.12 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | curl-0:7.76.1-23.el9_2.8 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | curl-0:7.76.1-29.el9_4.3 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | curl-0:7.76.1-31.el9_6.2 | * |
| Red Hat Discovery 2 | RedHat | discovery/discovery-server-rhel9:sha256:519d4fe184cebe5152f840e9f609fa4705590656ac9bcace2e2e17622ab7e6a8 | * |
| Red Hat Insights proxy 1.5 | RedHat | insights-proxy/insights-proxy-container-rhel9:sha256:975a1e501a8520df83f3f4114e72a71384ff1866ec99c7a45fffbf8c76ef5cbc | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-rhel9:sha256:48cf7cf48dfadb17f9357bf1894a5d0393551a893faa8b0ea0e11fe1ffed497f | * |
| Curl | Ubuntu | devel | * |
| Curl | Ubuntu | esm-infra-legacy/trusty | * |
| Curl | Ubuntu | esm-infra/bionic | * |
| Curl | Ubuntu | esm-infra/focal | * |
| Curl | Ubuntu | esm-infra/xenial | * |
| Curl | Ubuntu | jammy | * |
| Curl | Ubuntu | noble | * |
| Curl | Ubuntu | plucky | * |
| Curl | Ubuntu | questing | * |
| Curl | Ubuntu | upstream | * |