~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2013-1944

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2013-04-12 15:00:00 UTC
2
 
Candidate: CVE-2013-1944
3
 
CRD: 2013-04-12 15:00:00 UTC
4
 
PublicDate: 2013-04-29
5
 
References:
6
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1944
7
 
 http://curl.haxx.se/docs/adv_20130412.html
8
 
 https://usn.ubuntu.com/usn/usn-1801-1
9
 
Description:
10
 
 The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does
11
 
 not properly match the path domain when sending cookies, which allows
12
 
 remote attackers to steal cookies via a matching suffix in the domain of a
13
 
 URL.
14
 
Ubuntu-Description:
15
 
Notes: 
16
 
Bugs: 
17
 
Priority: medium
18
 
Discovered-by: YAMADA Yasuharu
19
 
Assigned-to: sarnold
20
 
 
21
 
Patches_curl:
22
 
 upstream: http://curl.haxx.se/curl-tailmatch.patch
23
 
upstream_curl: released (7.30.0)
24
 
hardy_curl: released (7.18.0-1ubuntu2.4)
25
 
lucid_curl: released (7.19.7-1ubuntu1.2)
26
 
oneiric_curl: released (7.21.6-3ubuntu3.3)
27
 
precise_curl: released (7.22.0-3ubuntu4.1)
28
 
quantal_curl: released (7.27.0-1ubuntu1.2)
29
 
devel_curl: released (7.29.0-1ubuntu3)