First published: Tue Nov 18 2014(Updated: )
cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Haxx Curl | <=7.37.1 | |
Haxx Curl | =7.31.0 | |
Haxx Curl | =7.32.0 | |
Haxx Curl | =7.33.0 | |
Haxx Curl | =7.34.0 | |
Haxx Curl | =7.35.0 | |
Haxx Curl | =7.36.0 | |
Haxx Curl | =7.37.0 | |
Haxx Libcurl | <=7.37.1 | |
Haxx Libcurl | =7.31.0 | |
Haxx Libcurl | =7.32.0 | |
Haxx Libcurl | =7.33.0 | |
Haxx Libcurl | =7.34.0 | |
Haxx Libcurl | =7.35.0 | |
Haxx Libcurl | =7.36.0 | |
Haxx Libcurl | =7.37.0 | |
Apple Mac OS X | <=10.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.