CVE-2014-3620
Publication date 10 September 2014
Last updated 24 July 2024
Ubuntu priority
cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.
Status
Package | Ubuntu Release | Status |
---|---|---|
curl | 14.04 LTS trusty |
Fixed 7.35.0-1ubuntu2.1
|
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2346-1
- curl vulnerabilities
- 15 September 2014