ISOMAN

CVE

CVE-2014-8150

CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.

Severity
MEDIUM
CVSS
4.3
Published
Modified

Linked Releases

References

  1. http://advisories.mageia.org/MGASA-2015-0020.html
  2. http://curl.haxx.se/docs/adv_20150108B.html
  3. http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
  4. http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
  5. http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147856.html
  6. http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147876.html
  7. http://lists.fedoraproject.org/pipermail/package-announce/2015-May/156945.html
  8. http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157188.html
  9. http://lists.opensuse.org/opensuse-updates/2015-02/msg00040.html
  10. http://rhn.redhat.com/errata/RHSA-2015-1254.html
  11. http://secunia.com/advisories/61925
  12. http://secunia.com/advisories/62075
  13. http://secunia.com/advisories/62361
  14. http://www.debian.org/security/2015/dsa-3122
  15. http://www.mandriva.com/security/advisories?name=MDVSA-2015:021
  16. http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
  17. http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
  18. http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
  19. http://www.securityfocus.com/bid/71964
  20. http://www.securitytracker.com/id/1032768