CVE-2014-8150: CRLF Injection
CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8150?
CVE-2014-8150 is classified as a medium severity vulnerability due to its potential for HTTP response splitting attacks.
How do I fix CVE-2014-8150?
To fix CVE-2014-8150, upgrade libcurl to version 7.40.0 or later, which contains the necessary security patches.
What systems are affected by CVE-2014-8150?
CVE-2014-8150 affects libcurl versions from 6.0 through 7.x before 7.40.0, as well as specific distributions like Debian and Ubuntu.
What types of attacks can CVE-2014-8150 facilitate?
CVE-2014-8150 can facilitate HTTP response splitting attacks by allowing remote attackers to inject arbitrary HTTP headers.
Is CVE-2014-8150 specific to certain versions of libcurl?
Yes, CVE-2014-8150 specifically affects libcurl versions 6.0 through 7.x before 7.40.0.