Oval Definition:oval:org.cisecurity:def:117
Revision Date:2016-02-08Version:2
Title:DSA-3122-1 -- curl -- security update
Description:Andrey Labunets of Facebook discovered that cURL, an URL transfer library, fails to properly handle URLs with embedded end-of-line characters. An attacker able to make an application using libcurl to access a specially crafted URL via an HTTP proxy could use this flaw to do additional requests in a way that was not intended, or insert additional request headers into the request.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2014-8150
DSA-3122-1
Platform(s):Debian GNU/kFreeBSD 7.0
Debian GNU/Linux 7.0
Product(s):curl
Definition Synopsis
  • Debian 7 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND curl is earlier than 0:7.26.0-1+wheezy12
  • BACK