MGASA-2014-0384

Source
https://advisories.mageia.org/MGASA-2014-0384.html
Import Source
https://advisories.mageia.org/MGASA-2014-0384.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0384
Related
Published
2014-09-24T16:44:28Z
Modified
2014-09-24T16:27:26Z
Summary
Updated curl packages fix security vulnerabilities
Details

Updated curl packages fix security vulnerabilities:

In cURL before 7.38.0, libcurl can be fooled to both sending cookies to wrong sites and into allowing arbitrary sites to set cookies for others. For this problem to trigger, the client application must use the numerical IP address in the URL to access the site (CVE-2014-3613).

References
Credits

Affected packages

Mageia:3 / curl

Package

Name
curl
Purl
pkg:rpm/mageia/curl?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.28.1-6.5.mga3

Ecosystem specific

{
    "section": "core"
}