SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-3613

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site…

MEDIUM 5.0EPSS 7.14%

Does this matter?

Lower severity and a low EPSS score (7.14%). Track it; it rarely justifies an emergency change on its own.

Description

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
7.14% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
haxx/curl · haxx/libcurl · apple/mac os x
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.