CVE-2014-8150
Summary
| CVE | CVE-2014-8150 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-01-15 15:59:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 10.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.10 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Application | Haxx | Libcurl | 6.0 | All | All | All |
| Application | Haxx | Libcurl | 6.1 | All | All | All |
| Application | Haxx | Libcurl | 6.1 | beta | All | All |
| Application | Haxx | Libcurl | 6.2 | All | All | All |
| Application | Haxx | Libcurl | 6.3 | All | All | All |
| Application | Haxx | Libcurl | 6.3.1 | All | All | All |
| Application | Haxx | Libcurl | 6.4 | All | All | All |
| Application | Haxx | Libcurl | 6.5 | All | All | All |
| Application | Haxx | Libcurl | 6.5.1 | All | All | All |
| Application | Haxx | Libcurl | 6.5.2 | All | All | All |
| Application | Haxx | Libcurl | 7.1 | All | All | All |
| Application | Haxx | Libcurl | 7.1.1 | All | All | All |
| Application | Haxx | Libcurl | 7.10 | All | All | All |
| Application | Haxx | Libcurl | 7.10.1 | All | All | All |
| Application | Haxx | Libcurl | 7.10.2 | All | All | All |
| Application | Haxx | Libcurl | 7.10.3 | All | All | All |
| Application | Haxx | Libcurl | 7.10.4 | All | All | All |
| Application | Haxx | Libcurl | 7.10.5 | All | All | All |
| Application | Haxx | Libcurl | 7.10.6 | All | All | All |
| Application | Haxx | Libcurl | 7.10.7 | All | All | All |
| Application | Haxx | Libcurl | 7.10.8 | All | All | All |
| Application | Haxx | Libcurl | 7.11.0 | All | All | All |
| Application | Haxx | Libcurl | 7.11.1 | All | All | All |
| Application | Haxx | Libcurl | 7.11.2 | All | All | All |
| Application | Haxx | Libcurl | 7.12.0 | All | All | All |
| Application | Haxx | Libcurl | 7.12.1 | All | All | All |
| Application | Haxx | Libcurl | 7.12.2 | All | All | All |
| Application | Haxx | Libcurl | 7.12.3 | All | All | All |
| Application | Haxx | Libcurl | 7.13.0 | All | All | All |
| Application | Haxx | Libcurl | 7.13.1 | All | All | All |
| Application | Haxx | Libcurl | 7.13.2 | All | All | All |
| Application | Haxx | Libcurl | 7.14.0 | All | All | All |
| Application | Haxx | Libcurl | 7.14.1 | All | All | All |
| Application | Haxx | Libcurl | 7.15.0 | All | All | All |
| Application | Haxx | Libcurl | 7.15.1 | All | All | All |
| Application | Haxx | Libcurl | 7.15.2 | All | All | All |
| Application | Haxx | Libcurl | 7.15.3 | All | All | All |
| Application | Haxx | Libcurl | 7.15.4 | All | All | All |
| Application | Haxx | Libcurl | 7.15.5 | All | All | All |
| Application | Haxx | Libcurl | 7.16.0 | All | All | All |
| Application | Haxx | Libcurl | 7.16.1 | All | All | All |
| Application | Haxx | Libcurl | 7.16.2 | All | All | All |
| Application | Haxx | Libcurl | 7.16.3 | All | All | All |
| Application | Haxx | Libcurl | 7.16.4 | All | All | All |
| Application | Haxx | Libcurl | 7.17.0 | All | All | All |
| Application | Haxx | Libcurl | 7.17.1 | All | All | All |
| Application | Haxx | Libcurl | 7.18.0 | All | All | All |
| Application | Haxx | Libcurl | 7.18.1 | All | All | All |
| Application | Haxx | Libcurl | 7.18.2 | All | All | All |
| Application | Haxx | Libcurl | 7.19.0 | All | All | All |
| Application | Haxx | Libcurl | 7.19.1 | All | All | All |
| Application | Haxx | Libcurl | 7.19.2 | All | All | All |
| Application | Haxx | Libcurl | 7.19.3 | All | All | All |
| Application | Haxx | Libcurl | 7.19.4 | All | All | All |
| Application | Haxx | Libcurl | 7.19.5 | All | All | All |
| Application | Haxx | Libcurl | 7.19.6 | All | All | All |
| Application | Haxx | Libcurl | 7.19.7 | All | All | All |
| Application | Haxx | Libcurl | 7.2 | All | All | All |
| Application | Haxx | Libcurl | 7.2.1 | All | All | All |
| Application | Haxx | Libcurl | 7.20.0 | All | All | All |
| Application | Haxx | Libcurl | 7.20.1 | All | All | All |
| Application | Haxx | Libcurl | 7.21.0 | All | All | All |
| Application | Haxx | Libcurl | 7.21.1 | All | All | All |
| Application | Haxx | Libcurl | 7.21.2 | All | All | All |
| Application | Haxx | Libcurl | 7.21.3 | All | All | All |
| Application | Haxx | Libcurl | 7.21.4 | All | All | All |
| Application | Haxx | Libcurl | 7.21.5 | All | All | All |
| Application | Haxx | Libcurl | 7.21.6 | All | All | All |
| Application | Haxx | Libcurl | 7.21.7 | All | All | All |
| Application | Haxx | Libcurl | 7.22.0 | All | All | All |
| Application | Haxx | Libcurl | 7.23.0 | All | All | All |
| Application | Haxx | Libcurl | 7.23.1 | All | All | All |
| Application | Haxx | Libcurl | 7.24.0 | All | All | All |
| Application | Haxx | Libcurl | 7.25.0 | All | All | All |
| Application | Haxx | Libcurl | 7.26.0 | All | All | All |
| Application | Haxx | Libcurl | 7.27.0 | All | All | All |
| Application | Haxx | Libcurl | 7.28.0 | All | All | All |
| Application | Haxx | Libcurl | 7.28.1 | All | All | All |
| Application | Haxx | Libcurl | 7.29.0 | All | All | All |
| Application | Haxx | Libcurl | 7.3 | All | All | All |
| Application | Haxx | Libcurl | 7.30.0 | All | All | All |
| Application | Haxx | Libcurl | 7.31.0 | All | All | All |
| Application | Haxx | Libcurl | 7.32.0 | All | All | All |
| Application | Haxx | Libcurl | 7.33.0 | All | All | All |
| Application | Haxx | Libcurl | 7.34.0 | All | All | All |
| Application | Haxx | Libcurl | 7.35.0 | All | All | All |
| Application | Haxx | Libcurl | 7.36.0 | All | All | All |
| Application | Haxx | Libcurl | 7.37.0 | All | All | All |
| Application | Haxx | Libcurl | 7.37.1 | All | All | All |
| Application | Haxx | Libcurl | 7.38.0 | All | All | All |
| Application | Haxx | Libcurl | 7.39 | All | All | All |
| Application | Haxx | Libcurl | 7.4 | All | All | All |
| Application | Haxx | Libcurl | 7.4.1 | All | All | All |
| Application | Haxx | Libcurl | 7.4.2 | All | All | All |
| Application | Haxx | Libcurl | 7.5 | All | All | All |
| Application | Haxx | Libcurl | 7.5.1 | All | All | All |
| Application | Haxx | Libcurl | 7.5.2 | All | All | All |
| Application | Haxx | Libcurl | 7.6 | All | All | All |
| Application | Haxx | Libcurl | 7.6.1 | All | All | All |
| Application | Haxx | Libcurl | 7.7 | All | All | All |
| Application | Haxx | Libcurl | 7.7.1 | All | All | All |
| Application | Haxx | Libcurl | 7.7.2 | All | All | All |
| Application | Haxx | Libcurl | 7.7.3 | All | All | All |
| Application | Haxx | Libcurl | 7.8 | All | All | All |
| Application | Haxx | Libcurl | 7.8.1 | All | All | All |
| Application | Haxx | Libcurl | 7.9 | All | All | All |
| Application | Haxx | Libcurl | 7.9.1 | All | All | All |
| Application | Haxx | Libcurl | 7.9.2 | All | All | All |
| Application | Haxx | Libcurl | 7.9.3 | All | All | All |
| Application | Haxx | Libcurl | 7.9.4 | All | All | All |
| Application | Haxx | Libcurl | 7.9.5 | All | All | All |
| Application | Haxx | Libcurl | 7.9.6 | All | All | All |
| Application | Haxx | Libcurl | 7.9.7 | All | All | All |
| Application | Haxx | Libcurl | 7.9.8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Tivoli Composite Application Manager libcurl Bug Lets Remote Authenticated Users Conduct HTTP Response Splitting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| cURL - URL request injection | af854a3a-2127-422b-91ae-364da2661108 | curl.haxx.se | Vendor Advisory |
| cURL/libcURL CVE-2014-8150 Remote Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Advisory SA62075 - Debian update for curl - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| McAfee KnowledgeBase - Intel Security - Security Bulletin: McAfee Agent patch fixes three Libcurl vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | kc.mcafee.com | |
| APPLE-SA-2015-08-13-2 OS X Yosemite v10.10.5 and Security Update 2015-006 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| [SECURITY] Fedora 21 Update: mingw-curl-7.42.0-1.fc21 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Security Advisory SA61925 - cURL / libcURL Header Injection Weakness and Certificate Verification Security Issue - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 20 Update: curl-7.32.0-18.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Oracle Bulletin Board Update - January 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Oracle Critical Patch Update - October 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| USN-2474-1: curl vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Support / Security / Advisories / / MDVSA-2015:021 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| 2016-04 Security Bulletin: Junos: Multiple vulnerabilities in cURL and libcurl - Juniper Networks | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | |
| Debian -- Security Information -- DSA-3122-1 curl | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Mageia Advisory: MGASA-2015-0020 - Updated curl packages fix CVE-2014-8150 | af854a3a-2127-422b-91ae-364da2661108 | advisories.mageia.org | |
| openSUSE-SU-2015:0248-1: moderate: Security update for curl | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Advisory SA62361 - Ubuntu update for curl - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 22 Update: mingw-curl-7.42.0-1.fc22 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Oracle Linux Bulletin - October 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [SECURITY] Fedora 21 Update: curl-7.37.0-12.fc21 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| cURL: Multiple vulnerabilities (GLSA 201701-47) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.