Wind River Support Network

HomeDefectsLIN1021-6918
Fixed

LIN1021-6918 : Security Advisory - curl - CVE-2023-46218

Created: Dec 7, 2023    Updated: Jan 22, 2024
Resolved Date: Jan 21, 2024
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
possible. This allows a site to set cookies that then would get sent to
different and unrelated sites and domains.

It could do this by exploiting a mixed case flaw in curl's function that
verifies a given cookie domain against the Public Suffix List (PSL). For
example a cookie could be set with `domain=co.UK` when the URL used a lower
case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.


https://nvd.nist.gov/vuln/detail/CVE-2023-46218

CVEs


Live chat
Online