CVE-2014-0138: Medium severity haxx curl vulnerability
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0138?
CVE-2014-0138 is classified as a moderate severity vulnerability.
How do I fix CVE-2014-0138?
To address CVE-2014-0138, update cURL or libcurl to a version greater than 7.36.0.
What systems are affected by CVE-2014-0138?
CVE-2014-0138 affects versions of cURL and libcurl from 7.10.6 up to 7.36.0.
What type of attack does CVE-2014-0138 enable?
CVE-2014-0138 allows context-dependent attackers to potentially connect as other users to services that reuse connections.
Is there a patch available for CVE-2014-0138?
Yes, upgrading to cURL or libcurl version 7.36.0 or later provides a patch for CVE-2014-0138.