Lucene search

K
f5F5F5:K15875
HistoryNov 27, 2014 - 12:00 a.m.

K15875 : cURL vulnerability CVE-2013-1944

2014-11-2700:00:00
my.f5.com
5

6.6 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.2%

Security Advisory Description

The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL. (CVE-2013-1944)

Impact

Allows unauthorized disclosure of information.