CVE-2014-0138
published 2014-04-15CVE-2014-0138: The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS…
PriorityP428medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
0.67%
71.8th percentile
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
Affected
139 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | curl | < curl 7.36.0-1 (bookworm) | curl 7.36.0-1 (bookworm) |
| debian | debian_linux | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv4.0MEDIUM
vendor_ubuntu6.4MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j832-g86m-353x: The default configuration in cURL and libcurl 7
ghsa_unreviewed·2022-05-14·CVSS 4.0
CVE-2014-0138 [MEDIUM] CWE-287 GHSA-j832-g86m-353x: The default configuration in cURL and libcurl 7
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
OSV
CVE-2014-0138: The default configuration in cURL and libcurl 7
osv·2014-04-15·CVSS 4.0
CVE-2014-0138 [MEDIUM] CVE-2014-0138: The default configuration in cURL and libcurl 7
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
CISA ICS
Hitachi Energy MSM Product
cisa_ics·2022-08-30·CVSS 4.3
[MEDIUM] Hitachi Energy MSM Product
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy MSM Product
Last RevisedAugust 30, 2022
Alert CodeICSA-22-242-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: MSM Product
- Vulnerability: Reliance on Uncontrolled Component
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could disrupt the functionality of the MSM web interface, steal sensitive user credentials, or cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Hitachi Energy reports multiple open-source softwar
VMware
VMware vSphere product updates address security vulnerabilities
vendor_vmware·2014-12-04·CVSS 4.3
CVE-2013-1752 [MEDIUM] VMware vSphere product updates address security vulnerabilities
VMSA-2014-0012: VMware vSphere product updates address security vulnerabilities
a. VMware vCSA cross-site scripting vulnerability VMware vCenter Server Appliance (vCSA) contains a vulnerability that may allow for Cross Site Scripting. Exploitation of this vulnerability in vCenter Server requires tricking a user to click on a malicious link or to open a malicious web page. VMware would like to thank Tanya Secker of Trustwave SpiderLabs for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-3797 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with/ Apply Patch VMware Pro
Ubuntu
curl vulnerabilities
vendor_ubuntu·2014-04-14·CVSS 6.4
CVE-2014-0138 [MEDIUM] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Steve Holme discovered that libcurl incorrectly reused wrong connections
when using protocols other than HTTP and FTP. This could lead to the use of
unintended credentials, possibly exposing sensitive information.
(CVE-2014-0138)
Richard Moore discovered that libcurl incorrectly validated wildcard SSL
certificates that contain literal IP addresses. An attacker could possibly
exploit this to perform a machine-in-the-middle attack to view sensitive
information or alter encrypted communications. (CVE-2014-0139)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
curl: wrong re-use of connections in libcurl
vendor_redhat·2014-03-26·CVSS 4.0
CVE-2014-0138 [MEDIUM] curl: wrong re-use of connections in libcurl
curl: wrong re-use of connections in libcurl
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
Statement: This issue affects the version of curl as shipped with Red Hat Enterprise Linux 5 and 7. The Red Hat Security Response Team has rated this issue as having Moderate security impact, a future update may address this flaw.
Package: curl (Red Hat Enterprise Linux 5) - Will not fix
Package: curl (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-0138: curl - The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) S...
vendor_debian·2014·CVSS 4.0
CVE-2014-0138 [MEDIUM] CVE-2014-0138: curl - The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) S...
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
Scope: local
bookworm: resolved (fixed in 7.36.0-1)
bullseye: resolved (fixed in 7.36.0-1)
forky: resolved (fixed in 7.36.0-1)
sid: resolved (fixed in 7.36.0-1)
trixie: resolved (fixed in 7.36.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0138 CVE-2014-0139 mingw32-curl: various flaws [epel-5]
bugzilla·2014-03-26·CVSS 6.4
CVE-2014-0138 [MEDIUM] CVE-2014-0138 CVE-2014-0139 mingw32-curl: various flaws [epel-5]
CVE-2014-0138 CVE-2014-0139 mingw32-curl: various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for mingw32-cur
Bugzilla
CVE-2014-0138 CVE-2014-0139 mingw-curl: various flaws [fedora-all]
bugzilla·2014-03-26·CVSS 6.4
CVE-2014-0138 [MEDIUM] CVE-2014-0138 CVE-2014-0139 mingw-curl: various flaws [fedora-all]
CVE-2014-0138 CVE-2014-0139 mingw-curl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multip
Bugzilla
CVE-2014-0138 curl: wrong re-use of connections in libcurl [fedora-all]
bugzilla·2014-03-26·CVSS 6.4
CVE-2014-0138 [MEDIUM] CVE-2014-0138 curl: wrong re-use of connections in libcurl [fedora-all]
CVE-2014-0138 curl: wrong re-use of connections in libcurl [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects m
Bugzilla
CVE-2014-0138 curl: wrong re-use of connections in libcurl
bugzilla·2014-03-21·CVSS 4.0
CVE-2014-0138 [MEDIUM] CVE-2014-0138 curl: wrong re-use of connections in libcurl
CVE-2014-0138 curl: wrong re-use of connections in libcurl
Daniel Stenberg reported the following vulnerability in cURL:
libcurl can in some circumstances re-use the wrong connection when asked to
do transfers using other protocols than HTTP and FTP.
libcurl features a pool of recent connections so that subsequent requests
can re-use an existing connection to avoid overhead.
When re-using a connection a range of criterion must first be met. Due to an
error in the code, a transfer that was initiated by an application could
wrongfully re-use an existing connection to the same server that was
authenticated using different credentials. The existing logic basically only
worked well enough for HTTP and FTP, while all other network protocols were
silently, but erroneously, assumed to work lik
http://curl.haxx.se/docs/adv_20140326A.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00042.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/57836http://secunia.com/advisories/57966http://secunia.com/advisories/57968http://secunia.com/advisories/58615http://secunia.com/advisories/59458http://www-01.ibm.com/support/docview.wss?uid=swg21675820http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862http://www.debian.org/security/2014/dsa-2902http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.ubuntu.com/usn/USN-2167-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttp://curl.haxx.se/docs/adv_20140326A.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00042.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/57836http://secunia.com/advisories/57966http://secunia.com/advisories/57968http://secunia.com/advisories/58615http://secunia.com/advisories/59458http://www-01.ibm.com/support/docview.wss?uid=swg21675820http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862http://www.debian.org/security/2014/dsa-2902http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.ubuntu.com/usn/USN-2167-1http://www.vmware.com/security/advisories/VMSA-2014-0012.html
2014-04-15
Published