Wind River Support Network

HomeDefectsLIN5-20059
Fixed

LIN5-20059 : Security Advisory - libcurl - CVE-2014-8150

Created: Feb 1, 2015    Updated: Dec 19, 2017
Resolved Date: Feb 4, 2015
Found In Version: 5.0.1.23
Fix Version: 5.0.1.24
Severity: Standard
Applicable for: Wind River Linux 5
Component/s: Userspace

Description

CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.<a href=http://cwe.mitre.org/data/definitions/93.html target=_blank>CWE-93: CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')</a>

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8150

Other Downloads


Live chat
Online