CVE-2018-6651
Summary
| CVE | CVE-2018-6651 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-05 22:29:00 UTC |
| Updated | 2019-10-09 23:41:00 UTC |
| Description | In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions. In Parsec, this means full control over the victim's computer. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Parsecgaming | Parsec | All | All | All | All |
| Application | Parsecgaming | Parsec | All | All | All | All |
| Application | Uncurl Project | Uncurl | All | All | All | All |
| Application | Uncurl Project | Uncurl | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release 0.07 · matoya/uncurl · GitHub | CONFIRM | github.com | Third Party Advisory |
| Parsec CSRF vulnerability in version 140-1 and prior · GitHub | MISC | gist.github.com | |
| origin matching must come at str end · matoya/uncurl@448cd13 · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.