First published: Tue Oct 25 2016(Updated: )
A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie jar.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/curl | <7.51.0 | 7.51.0 |
Curl | <7.51.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8615 has a moderate severity rating due to the potential for cookie injection from malicious HTTP servers.
To fix CVE-2016-8615, upgrade curl to version 7.51.0 or later.
The risks include unauthorized access to user sessions and the ability for attackers to manipulate user cookies if exploited.
CVE-2016-8615 affects curl versions prior to 7.51.0.
Yes, CVE-2016-8615 can be remotely exploited by a malicious HTTP server.