CVE-2014-3613
published 2014-11-18CVE-2014-3613: cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.82%
83.3th percentile
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.4 | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | curl | < curl 7.38.0-1 (bookworm) | curl 7.38.0-1 (bookworm) |
| haxx | curl | <= 7.37.1 | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | >= 0 < 7.38.0-1 | 7.38.0-1 |
| haxx | curl | >= 0 < 7.38.0-1 | 7.38.0-1 |
| haxx | curl | >= 0 < 7.38.0-1 | 7.38.0-1 |
| haxx | curl | >= 0 < 7.38.0-1 | 7.38.0-1 |
| haxx | curl | >= 0 < 7.35.0-1ubuntu2.1 | 7.35.0-1ubuntu2.1 |
| haxx | libcurl | <= 7.37.1 | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2014-09-15·CVSS 5.0
CVE-2014-3613 [MEDIUM] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Tim Ruehsen discovered that curl incorrectly handled partial literal IP
addresses. This could lead to the disclosure of cookies to the wrong site,
and malicious sites being able to set cookies for others. (CVE-2014-3613)
Tim Ruehsen discovered that curl incorrectly allowed cookies to be set
for Top Level Domains (TLDs). This could allow a malicious site to set a
cookie that gets sent to other sites. (CVE-2014-3620)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
curl: incorrect handling of IP addresses in cookie domain
vendor_redhat·2014-09-10·CVSS 5.0
CVE-2014-3613 [MEDIUM] CWE-20 curl: incorrect handling of IP addresses in cookie domain
curl: incorrect handling of IP addresses in cookie domain
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
It was found that the libcurl library did not correctly handle partial literal IP addresses when parsing received HTTP cookies. An attacker able to trick a user into connecting to a malicious server could use this flaw to set the user's cookie to a crafted domain, making other cookie-related issues easier to exploit.
Statement: This issue affects the versions of curl as shipped with Red Hat Enterprise Linux 5 and is not planned to be corrected in future updates.
In
Debian
CVE-2014-3613: curl - cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie d...
vendor_debian·2014·CVSS 5.0
CVE-2014-3613 [MEDIUM] CVE-2014-3613: curl - cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie d...
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
Scope: local
bookworm: resolved (fixed in 7.38.0-1)
bullseye: resolved (fixed in 7.38.0-1)
forky: resolved (fixed in 7.38.0-1)
sid: resolved (fixed in 7.38.0-1)
trixie: resolved (fixed in 7.38.0-1)
Apple
CVE-2014-3613: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 5.0
CVE-2014-3613 [MEDIUM] CVE-2014-3613: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2014-3613
Component: CVE-2014-3613
GHSA
GHSA-gcmw-6qh5-324w: cURL and libcurl before 7
ghsa_unreviewed·2022-05-14
CVE-2014-3613 [MEDIUM] GHSA-gcmw-6qh5-324w: cURL and libcurl before 7
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
OSV
CVE-2014-3613: cURL and libcurl before 7
osv·2014-11-18·CVSS 5.0
CVE-2014-3613 [MEDIUM] CVE-2014-3613: cURL and libcurl before 7
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
OSV
curl vulnerabilities
osv·2014-09-15·CVSS 5.0
CVE-2014-3613 [MEDIUM] curl vulnerabilities
curl vulnerabilities
Tim Ruehsen discovered that curl incorrectly handled partial literal IP
addresses. This could lead to the disclosure of cookies to the wrong site,
and malicious sites being able to set cookies for others. (CVE-2014-3613)
Tim Ruehsen discovered that curl incorrectly allowed cookies to be set
for Top Level Domains (TLDs). This could allow a malicious site to set a
cookie that gets sent to other sites. (CVE-2014-3620)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3620 CVE-2014-3613 mingw-curl: various flaws [epel-7]
bugzilla·2014-09-10·CVSS 5.0
CVE-2014-3620 [MEDIUM] CVE-2014-3620 CVE-2014-3613 mingw-curl: various flaws [epel-7]
CVE-2014-3620 CVE-2014-3613 mingw-curl: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for mingw-curl: see blocks bug list for full d
Bugzilla
CVE-2014-3620 CVE-2014-3613 mingw-curl: various flaws [fedora-all]
bugzilla·2014-09-10·CVSS 5.0
CVE-2014-3620 [MEDIUM] CVE-2014-3620 CVE-2014-3613 mingw-curl: various flaws [fedora-all]
CVE-2014-3620 CVE-2014-3613 mingw-curl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2014-3613 curl: incorrect handling of IP addresses in cookie domain [fedora-all]
bugzilla·2014-09-10·CVSS 5.0
CVE-2014-3613 [MEDIUM] CVE-2014-3613 curl: incorrect handling of IP addresses in cookie domain [fedora-all]
CVE-2014-3613 curl: incorrect handling of IP addresses in cookie domain [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2014-3613 curl: incorrect handling of IP addresses in cookie domain
bugzilla·2014-09-02·CVSS 5.0
CVE-2014-3613 [MEDIUM] CVE-2014-3613 curl: incorrect handling of IP addresses in cookie domain
CVE-2014-3613 curl: incorrect handling of IP addresses in cookie domain
Daniel Stenberg reported the following vulnerability in cURL that could cause libcurl-based HTTP clients to leak cookie information:
IP address as domain problem
By not detecting and rejecting domain names for partial literal IP addresses
properly when parsing received HTTP cookies, libcurl can be fooled to both
sending cookies to wrong sites and into allowing arbitrary sites to set
cookies for others.
For this problem to trigger, the client application must use the numerical
IP address in the URL to access the site and the site must send back cookies
to the site using domain= and a partial IP address.
Since libcurl wrongly approaches the IP address like it was a normal domain
name, a site at IP address 192.168.0.
http://curl.haxx.se/docs/adv_20140910A.htmlhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1254.htmlhttp://www.debian.org/security/2014/dsa-3022http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/69748https://support.apple.com/kb/HT205031http://curl.haxx.se/docs/adv_20140910A.htmlhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1254.htmlhttp://www.debian.org/security/2014/dsa-3022http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/69748https://support.apple.com/kb/HT205031
2014-11-18
Published