CVE-2015-3153
Description
The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
9.76
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerability CVE-2015-3153 are affected in Curl For Windows 7.42.0 | Windows |
| Multiple Vulnerabilities are affected in Curl For Windows 7.42.0 | Windows |
| Vulnerabilities CVE-2015-3153 are fixed in Curl For Windows 7.42.1 | Windows |
| Multiple vulnerabilities are fixed in OS X Yosemite 10.10.5 Update | Mac |
| Multiple vulnerabilities are fixed in OS X Yosemite 10.10.5 Combo Update | Mac |
| HTTP, HTTPS, and FTP client and client libraries (USN-2591-1) libcurl3_7.38.0-3ubuntu2.2_i386.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-2591-1) libcurl3_7.38.0-3ubuntu2.2_amd64.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-2591-1) libcurl3-nss_7.38.0-3ubuntu2.2_i386.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-2591-1) libcurl3-nss_7.38.0-3ubuntu2.2_amd64.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-2591-1) libcurl3-gnutls_7.38.0-3ubuntu2.2_i386.deb | Linux |
| HTTP, HTTPS, and FTP client and client libraries (USN-2591-1) libcurl3-gnutls_7.38.0-3ubuntu2.2_amd64.deb | Linux |
| Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3153) | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-600354 | OS X Yosemite 10.10.5 Update |
| PATCH-600458 | OS X Yosemite 10.10.5 Combo Update |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234