CVE-2014-8150

NameCVE-2014-8150
DescriptionCRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-134-1, DSA-3122-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
curl (PTS)wheezy7.26.0-1+wheezy13fixed
wheezy (security)7.26.0-1+wheezy21fixed
jessie7.38.0-4+deb8u5fixed
jessie (security)7.38.0-4+deb8u6fixed
stretch7.52.1-5fixed
stretch (security)7.52.1-5+deb9u1fixed
buster, sid7.55.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
curlsource(unstable)7.38.0-4medium
curlsourcesqueeze7.21.0-2.1+squeeze11mediumDLA-134-1
curlsourcewheezy7.26.0-1+wheezy12mediumDSA-3122-1

Notes

http://curl.haxx.se/docs/adv_20150108B.html

Search for package or bug name: Reporting problems