CVE-2014-3613
Last modified
CVE-2014-3613 is a vulnerability of currently unknown severity. cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.. EPSS estimates a 7.43% chance of exploitation in the next 30 days.
Description
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Haxx | Curl | <= 7.37.1 |
| Haxx | Curl | 7.31.0 |
| Haxx | Curl | 7.32.0 |
| Haxx | Curl | 7.33.0 |
| Haxx | Curl | 7.34.0 |
| Haxx | Curl | 7.35.0 |
| Haxx | Curl | 7.36.0 |
| Haxx | Curl | 7.37.0 |
| Haxx | Libcurl | <= 7.37.1 |
| Haxx | Libcurl | 7.31.0 |
| Haxx | Libcurl | 7.32.0 |
| Haxx | Libcurl | 7.33.0 |
| Haxx | Libcurl | 7.34.0 |
| Haxx | Libcurl | 7.35.0 |
| Haxx | Libcurl | 7.36.0 |
| Haxx | Libcurl | 7.37.0 |
| Apple | Mac Os X | <= 10.10.4 |
References
- http://www.debian.org/security/2014/dsa-3022Vendor Advisory
- http://www.debian.org/security/2014/dsa-3022Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3613?
How severe is CVE-2014-3613?
How do I fix CVE-2014-3613?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-3607DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does …
- CVE-2014-3608The VMWare driver in OpenStack Compute (Nova) before 2014.1.…
- CVE-2014-3609HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before …
- CVE-2014-3610The WRMSR processing functionality in the KVM subsystem in t…5.5
- CVE-2014-3611Race condition in the __kvm_migrate_pit_timer function in ar…4.7
- CVE-2014-3612The LDAPLoginModule implementation in the Java Authenticatio…
- CVE-2014-3614Unspecified vulnerability in PowerDNS Recursor (aka pdns_rec…
- CVE-2014-3615The VGA emulator in QEMU allows local guest users to read ho…
- CVE-2014-3616nginx 0.5.6 through 1.7.4, when using the same shared ssl_se…
- CVE-2014-3617The forum_print_latest_discussions function in mod/forum/lib…
- CVE-2014-3618Heap-based buffer overflow in formisc.c in formail in procma…
- CVE-2014-3619The __socket_proto_state_machine function in GlusterFS 3.5 a…
Are you affected by CVE-2014-3613?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
