CVE-2015-3153
Summary
| CVE | CVE-2015-3153 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-05-01 15:59:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | 10.10.4 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 15.1 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Haxx | Curl | All | All | All | All |
| Application | Haxx | Libcurl | All | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.2.0 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.2.1 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.3.0 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CPU Oct 2018 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Debian -- Security Information -- DSA-3240-1 curl | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| McAfee KnowledgeBase - Intel Security - Security Bulletin: McAfee Agent patch fixes three Libcurl vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | kc.mcafee.com | |
| APPLE-SA-2015-08-13-2 OS X Yosemite v10.10.5 and Security Update 2015-006 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List, Third Party Advisory |
| About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| Oracle Critical Patch Update - October 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| USN-2591-1: curl vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| 2016-04 Security Bulletin: Junos: Multiple vulnerabilities in cURL and libcurl - Juniper Networks | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | |
| libcurl CURLOPT_HTTPHEADER Option Discloses Potentially Sensitive Information to Remote Users - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| cURL - sensitive HTTP server headers also sent to proxies | af854a3a-2127-422b-91ae-364da2661108 | curl.haxx.se | Vendor Advisory |
| Oracle Solaris Bulletin - January 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Oracle Critical Patch Update - January 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| openSUSE-SU-2015:0861-1: moderate: Security update for curl | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| cURL/libcURL CVE-2015-3153 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.