Debian Security Advisory
DLA-134-1 curl -- LTS security update
- Date Reported:
- 15 Jan 2015
- Affected Packages:
- curl
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2014-8150.
- More information:
-
Andrey Labunets of Facebook discovered that cURL, an URL transfer library, fails to properly handle URLs with embedded end-of-line characters. An attacker able to make an application using libcurl to access a specially crafted URL via an HTTP proxy could use this flaw to do additional requests in a way that was not intended, or insert additional request headers into the request.
For Debian 6
Squeeze
, these issues have been fixed in curl version 7.21.0-2.1+squeeze11