ISOMAN

CVE

CVE-2015-3153

The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.

Severity
MEDIUM
CVSS
5
Published
Modified

Linked Releases

References

  1. http://curl.haxx.se/docs/adv_20150429.html
  2. http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
  3. http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
  4. http://lists.opensuse.org/opensuse-updates/2015-05/msg00017.html
  5. http://www.debian.org/security/2015/dsa-3240
  6. http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
  7. http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
  8. http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
  9. http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
  10. http://www.securityfocus.com/bid/74408
  11. http://www.securitytracker.com/id/1032233
  12. http://www.ubuntu.com/usn/USN-2591-1
  13. https://kc.mcafee.com/corporate/index?page=content&id=SB10131
  14. https://support.apple.com/kb/HT205031
  15. http://curl.haxx.se/docs/adv_20150429.html
  16. http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
  17. http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
  18. http://lists.opensuse.org/opensuse-updates/2015-05/msg00017.html
  19. http://www.debian.org/security/2015/dsa-3240
  20. http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html