![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2014-3613 |
Description: | cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1. |
Test IDs: | 1.3.6.1.4.1.25623.1.1.1.2.2014.64 1.3.6.1.4.1.25623.1.1.10.2014.0384 1.3.6.1.4.1.25623.1.0.703022 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-3613 http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html BugTraq ID: 69748 http://www.securityfocus.com/bid/69748 Debian Security Information: DSA-3022 (Google Search) http://www.debian.org/security/2014/dsa-3022 RedHat Security Advisories: RHSA-2015:1254 http://rhn.redhat.com/errata/RHSA-2015-1254.html SuSE Security Announcement: openSUSE-SU-2014:1139 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00024.html |