Oval Definition:oval:org.mitre.oval:def:20032
Revision Date:2014-06-23Version:6
Title:DSA-2660-1 curl - cookie leak vulnerability
Description:Yamada Yasuharu discovered that cURL, an URL transfer library, is vulnerable to expose potentially sensitive information when doing requests across domains with matching tails. Due to a bug in the tail match function when matching domain names, it was possible that cookies set for a domain ample.com could accidentally also be sent by libcurl when communicating with example.com.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2013-1944
DSA-2660-1
Platform(s):Debian GNU/kFreeBSD 6.0
Debian GNU/Linux 6.0
Product(s):curl
Definition Synopsis
  • Debian 6.0 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND curl DPKG is earlier than 0:7.21.0-2.1+squeeze3
  • BACK