[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2024-2531 --- curl

ID: oval:org.secpod.oval:def:1702254Date: (C)2024-05-09   (M)2024-05-09
Class: PATCHFamily: unix




This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains.It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List . For example a cookie could be set with domain=co.UK when the URL used a lowercase hostname curl.co.uk, even though co.uk is listed as a PSL domain

Platform:
Amazon Linux 2
Product:
curl
libcurl
Reference:
ALAS2-2024-2531
CVE-2023-46218
CVE    1
CVE-2023-46218

© SecPod Technologies