Oval Definition:
oval:org.mitre.oval:def:20280
Revision Date
:
2014-02-17
Version
:
12
Title
:
RHSA-2013:0771: curl security update (Moderate)
Description
:
The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.
Family
:
unix
Class
:
patch
Status
:
ACCEPTED
Reference(s)
:
CESA-2013:0771
CVE-2013-1944
RHSA-2013:0771-01
Platform(s)
:
CentOS Linux 5
CentOS Linux 6
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Product(s)
:
curl
Definition Synopsis
Operation system section
Redhat 6 or Centos 6 release
The operating system installed on the system is Red Hat Enterprise Linux 6
OR
The operating system installed on the system is CentOS Linux 6.x
AND
Packages section
curl is earlier than 0:7.19.7-36.el6_4
OR
libcurl-devel is earlier than 0:7.19.7-36.el6_4
OR
libcurl is earlier than 0:7.19.7-36.el6_4
Operation system section
Redhat 5 or Centos 5 release
The operating system installed on the system is Red Hat Enterprise Linux 5
OR
The operating system installed on the system is CentOS Linux 5.x
AND
Packages section
curl is earlier than 0:7.15.5-16.el5_9
OR
curl-devel is earlier than 0:7.15.5-16.el5_9
BACK