CVE-2014-3613
Description
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
Risk Information
Base Score
3.7
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
1.82
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerability CVE-2014-3613,CVE-2014-3620 are affected in Curl For Windows 7.37.1 | Windows |
| Multiple Vulnerabilities are affected in Curl For Windows 7.31.0 | Windows |
| Multiple Vulnerabilities are affected in Curl For Windows 7.32.0 | Windows |
| Multiple Vulnerabilities are affected in Curl For Windows 7.33.0 | Windows |
| Multiple Vulnerabilities are affected in Curl For Windows 7.34.0 | Windows |
| Multiple Vulnerabilities are affected in Curl For Windows 7.35.0 | Windows |
| Multiple Vulnerabilities are affected in Curl For Windows 7.36.0 | Windows |
| Multiple Vulnerabilities are affected in Curl For Windows 7.37.0 | Windows |
| Multiple Vulnerabilities are affected in Curl For Windows 7.37.1 | Windows |
| Vulnerabilities CVE-2014-3620,CVE-2014-3613 are fixed in Curl For Windows 7.38.0 | Windows |
| Multiple vulnerabilities are fixed in OS X Yosemite 10.10.5 Update | Mac |
| Multiple vulnerabilities are fixed in OS X Yosemite 10.10.5 Combo Update | Mac |
| HTTP, HTTPS, and FTP client and client libraries (USN-2346-1) libcurl3_7.35.0-1ubuntu2.5_i386.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-2346-1) libcurl3_7.35.0-1ubuntu2.5_amd64.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-2346-1) libcurl3-nss_7.35.0-1ubuntu2.5_i386.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-2346-1) libcurl3-nss_7.35.0-1ubuntu2.5_amd64.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-2346-1) libcurl3-nss_7.22.0-3ubuntu4.14_i386.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-2346-1) libcurl3-nss_7.22.0-3ubuntu4.14_amd64.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-2346-1) libcurl3-gnutls_7.35.0-1ubuntu2.5_i386.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-2346-1) libcurl3-gnutls_7.35.0-1ubuntu2.5_amd64.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-2346-1) libcurl3-gnutls_7.22.0-3ubuntu4.14_i386.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-2346-1) libcurl3-gnutls_7.22.0-3ubuntu4.14_amd64.deb | Linux |
| Curl 7.35.0-1ubuntu2.10 for Ubuntu 14.04 LTS (x64) curl_7.35.0-1ubuntu2.10_amd64.deb | Linux |
| Curl 7.35.0-1ubuntu2.10 for Ubuntu 14.04 LTS curl_7.35.0-1ubuntu2.10_i386.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-3498-1) curl_7.35.0-1ubuntu2.14_i386.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-3498-1) curl_7.35.0-1ubuntu2.14_amd64.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-3498-1) libcurl3_7.35.0-1ubuntu2.14_i386.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-3498-1) libcurl3_7.35.0-1ubuntu2.14_amd64.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-3498-1) libcurl3-nss_7.35.0-1ubuntu2.14_i386.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-3498-1) libcurl3-nss_7.35.0-1ubuntu2.14_amd64.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-3498-1) libcurl3-gnutls_7.35.0-1ubuntu2.14_i386.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-3498-1) libcurl3-gnutls_7.35.0-1ubuntu2.14_amd64.deb | Linux |
| curl security update(DSA-3232-1) curl_7.26.0-1+wheezy13_i386.deb | Linux |
| CVE-2014-3613 | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-600354 | OS X Yosemite 10.10.5 Update |
| PATCH-600458 | OS X Yosemite 10.10.5 Combo Update |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234