CVE-2014-3613
Summary
| CVE | CVE-2014-3613 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-11-18 15:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | All | All | All | All |
| Application | Haxx | Curl | 7.31.0 | All | All | All |
| Application | Haxx | Curl | 7.32.0 | All | All | All |
| Application | Haxx | Curl | 7.33.0 | All | All | All |
| Application | Haxx | Curl | 7.34.0 | All | All | All |
| Application | Haxx | Curl | 7.35.0 | All | All | All |
| Application | Haxx | Curl | 7.36.0 | All | All | All |
| Application | Haxx | Curl | 7.37.0 | All | All | All |
| Application | Haxx | Curl | All | All | All | All |
| Application | Haxx | Libcurl | 7.31.0 | All | All | All |
| Application | Haxx | Libcurl | 7.32.0 | All | All | All |
| Application | Haxx | Libcurl | 7.33.0 | All | All | All |
| Application | Haxx | Libcurl | 7.34.0 | All | All | All |
| Application | Haxx | Libcurl | 7.35.0 | All | All | All |
| Application | Haxx | Libcurl | 7.36.0 | All | All | All |
| Application | Haxx | Libcurl | 7.37.0 | All | All | All |
| Application | Haxx | Libcurl | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cURL/libcURL CVE-2014-3613 Remote Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| APPLE-SA-2015-08-13-2 OS X Yosemite v10.10.5 and Security Update 2015-006 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| [security-announce] openSUSE-SU-2014:1139-1: important: curl | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Oracle Critical Patch Update - July 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Debian -- Security Information -- DSA-3022-1 curl | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Vendor Advisory |
| 2016-04 Security Bulletin: Junos: Multiple vulnerabilities in cURL and libcurl - Juniper Networks | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | |
| Oracle Critical Patch Update - October 2017 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Oracle Linux Bulletin - October 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| cURL - libcurl cookie leak with IP address as domain | af854a3a-2127-422b-91ae-364da2661108 | curl.haxx.se | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.