← Back

CVE-2015-3145

nvd nist
Published: Apr 24, 2015Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character.

Affected (41)

Show all products
1 product
Fedora
1 product
Ubuntu Linux
1 product
Debian Linux
2 products
Curl
Libcurl
1 product
Mac Os X
1 product
Solaris
1 product
System Management Homepage
1 product
Opensuse
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 21
Version 22
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 14.10
Version 15.04
Version 7.0
Configuration C
12 vulnerable
Vulnerable SoftwareAffected Versions
Haxx
Version 7.31.0
Version 7.32.0
Version 7.33.0
Version 7.34.0
Version 7.35.0
Version 7.36.0
Version 7.37.0
Version 7.37.1
Version 7.38.0
Version 7.39.0
Version 7.40.0
Version 7.41.0
Configuration D
5 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Version 10.10.0
Version 10.10.1
Version 10.10.2
Version 10.10.3
Version 10.10.4
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.3
Configuration F
13 vulnerable
Vulnerable SoftwareAffected Versions
Haxx
Version 7.30.0
Version 7.31.0
Version 7.32.0
Version 7.33.0
Version 7.34.0
Version 7.35.0
Version 7.36.0
Version 7.37.0
Version 7.37.1
Version 7.38.0
Version 7.39
Version 7.40.0
Version 7.41.0
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 7.5.3.1
Configuration H
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 13.1
Version 13.2

References (40)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.