curl: URL request injection vulnerability in parseurlandfillconn()
Published Jan 15, 2015
4.3
MEDIUMCVSS 2.0
EPSS 6.81%
Description
CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.
Affected products
No data.
Configuration 1
- 7.0
Configuration 2
- 6.0
- 6.1
- 6.1
- 6.2
- 6.3
- 6.3.1
- 6.4
- 6.5
- 6.5.1
- 6.5.2
- 7.1
- 7.1.1
- 7.2
- 7.2.1
- 7.3
- 7.4
- 7.4.1
- 7.4.2
- 7.5
- 7.5.1
- 7.5.2
- 7.6
- 7.6.1
- 7.7
- 7.7.1
- 7.7.2
- 7.7.3
- 7.8
- 7.8.1
- 7.9
- 7.9.1
- 7.9.2
- 7.9.3
- 7.9.4
- 7.9.5
- 7.9.6
- 7.9.7
- 7.9.8
- 7.10
- 7.10.1
- 7.10.2
- 7.10.3
- 7.10.4
- 7.10.5
- 7.10.6
- 7.10.7
- 7.10.8
- 7.11.0
- 7.11.1
- 7.11.2
- 7.12.0
- 7.12.1
- 7.12.2
- 7.12.3
- 7.13.0
- 7.13.1
- 7.13.2
- 7.14.0
- 7.14.1
- 7.15.0
- 7.15.1
- 7.15.2
- 7.15.3
- 7.15.4
- 7.15.5
- 7.16.0
- 7.16.1
- 7.16.2
- 7.16.3
- 7.16.4
- 7.17.0
- 7.17.1
- 7.18.0
- 7.18.1
- 7.18.2
- 7.19.0
- 7.19.1
- 7.19.2
- 7.19.3
- 7.19.4
- 7.19.5
- 7.19.6
- 7.19.7
- 7.20.0
- 7.20.1
- 7.21.0
- 7.21.1
- 7.21.2
- 7.21.3
- 7.21.4
- 7.21.5
- 7.21.6
- 7.21.7
- 7.22.0
- 7.23.0
- 7.23.1
- 7.24.0
- 7.25.0
- 7.26.0
- 7.27.0
- 7.28.0
- 7.28.1
- 7.29.0
- 7.30.0
- 7.31.0
- 7.32.0
- 7.33.0
- 7.34.0
- 7.35.0
- 7.36.0
- 7.37.0
- 7.37.1
- 7.38.0
- 7.39
Configuration 3
- 10.04
- 12.04
- 14.04
- 14.10
No data.
Red Hat Enterprise Linux 6
curl-0:7.19.7-46.el6
Fixed · RHSA-2015:1254
Red Hat Enterprise Linux 7
curl-0:7.29.0-25.el7
Fixed · RHSA-2015:2159
Red Hat Enterprise Linux 4
curl
Will not fix
Red Hat Enterprise Linux 5
curl
Will not fix
Red Hat Enterprise Virtualization 3
mingw-virt-viewer
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | curl-0:7.19.7-46.el6 | Fixed | RHSA-2015:1254 |
| Red Hat Enterprise Linux 7 | curl-0:7.29.0-25.el7 | Fixed | RHSA-2015:2159 |
| Red Hat Enterprise Linux 4 | curl | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | curl | Will not fix | n/a |
| Red Hat Enterprise Virtualization 3 | mingw-virt-viewer | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
References (28)
- http://advisories.mageia.org/MGASA-2015-0020.html x_refsource_CONFIRM
- http://curl.haxx.se/docs/adv_20150108B.html x_refsource_CONFIRMVendor Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147856.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147876.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/156945.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157188.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00040.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2015-1254.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/61925 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62075 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62361 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2015/dsa-3122 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:021 vendor-advisoryx_refsource_MANDRIVA
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/71964 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1032768 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-2474-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2014-8150 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1178692 Issue Tracking
- https://kc.mcafee.com/corporate/index?page=content&id=SB10131 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2014-8150
- https://security.gentoo.org/glsa/201701-47 vendor-advisoryx_refsource_GENTOO
- https://support.apple.com/kb/HT205031 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2014-8150
Change history (0)
No recorded changes yet.