6.4
CVSSv2

CVE-2014-0138

Published: 15/04/2014 Updated: 09/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The default configuration in cURL and libcurl 7.10.6 prior to 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent malicious users to connect as other users via a request, a similar issue to CVE-2014-0015.

Vulnerable Product Search on Vulmon Subscribe to Product

haxx curl 7.10.6

haxx curl 7.12.2

haxx curl 7.12.3

haxx curl 7.15.1

haxx curl 7.15.2

haxx curl 7.16.3

haxx curl 7.16.4

haxx curl 7.19.2

haxx curl 7.19.3

haxx curl 7.21.0

haxx curl 7.21.1

haxx curl 7.22.0

haxx curl 7.23.0

haxx curl 7.23.1

haxx curl 7.29.0

haxx curl 7.30.0

haxx libcurl 7.10.8

haxx libcurl 7.11.0

haxx libcurl 7.13.1

haxx libcurl 7.13.2

haxx libcurl 7.15.4

haxx libcurl 7.15.5

haxx libcurl 7.17.1

haxx libcurl 7.18.0

haxx curl 7.10.7

haxx curl 7.10.8

haxx curl 7.13.0

haxx curl 7.13.1

haxx curl 7.15.3

haxx curl 7.15.4

haxx curl 7.17.0

haxx curl 7.17.1

haxx curl 7.18.0

haxx curl 7.19.4

haxx curl 7.19.5

haxx curl 7.21.2

haxx curl 7.21.3

haxx curl 7.24.0

haxx curl 7.25.0

haxx curl 7.31.0

haxx curl 7.32.0

haxx libcurl 7.11.1

haxx libcurl 7.11.2

haxx libcurl 7.14.0

haxx libcurl 7.14.1

haxx libcurl 7.16.0

haxx libcurl 7.16.1

haxx libcurl 7.18.1

haxx libcurl 7.18.2

haxx libcurl 7.19.7

haxx libcurl 7.20.0

haxx libcurl 7.21.5

haxx libcurl 7.21.6

haxx libcurl 7.26.0

haxx libcurl 7.27.0

haxx libcurl 7.34.0

haxx curl 7.35.0

haxx curl 7.12.0

haxx curl 7.12.1

haxx curl 7.14.1

haxx curl 7.15.0

haxx curl 7.16.1

haxx curl 7.16.2

haxx curl 7.19.0

haxx curl 7.19.1

haxx curl 7.20.0

haxx curl 7.20.1

haxx curl 7.21.6

haxx curl 7.21.7

haxx curl 7.28.0

haxx curl 7.28.1

haxx libcurl 7.10.6

haxx libcurl 7.10.7

haxx libcurl 7.12.2

haxx libcurl 7.12.3

haxx libcurl 7.13.0

haxx libcurl 7.15.2

haxx libcurl 7.15.3

haxx libcurl 7.16.4

haxx libcurl 7.17.0

haxx libcurl 7.19.3

haxx libcurl 7.19.4

haxx libcurl 7.21.1

haxx libcurl 7.21.2

haxx libcurl 7.23.0

haxx libcurl 7.23.1

haxx libcurl 7.30.0

haxx libcurl 7.31.0

haxx libcurl 7.19.5

haxx libcurl 7.19.6

haxx libcurl 7.21.3

haxx libcurl 7.21.4

haxx libcurl 7.24.0

haxx libcurl 7.25.0

haxx libcurl 7.32.0

haxx libcurl 7.33.0

haxx curl 7.11.0

haxx curl 7.11.1

haxx curl 7.11.2

haxx curl 7.13.2

haxx curl 7.14.0

haxx curl 7.15.5

haxx curl 7.16.0

haxx curl 7.18.1

haxx curl 7.18.2

haxx curl 7.19.6

haxx curl 7.19.7

haxx curl 7.21.4

haxx curl 7.21.5

haxx curl 7.26.0

haxx curl 7.27.0

haxx curl 7.33.0

haxx curl 7.34.0

haxx libcurl 7.12.0

haxx libcurl 7.12.1

haxx libcurl 7.15.0

haxx libcurl 7.15.1

haxx libcurl 7.16.2

haxx libcurl 7.16.3

haxx libcurl 7.19.0

haxx libcurl 7.19.1

haxx libcurl 7.19.2

haxx libcurl 7.20.1

haxx libcurl 7.21.0

haxx libcurl 7.21.7

haxx libcurl 7.22.0

haxx libcurl 7.28.0

haxx libcurl 7.28.1

haxx libcurl 7.29.0

haxx libcurl 7.35.0

debian debian linux 7.0

Vendor Advisories

Debian Bug report logs - #742728 curl: CVE-2014-0138 CVE-2014-0139 Package: curl; Maintainer for curl is Alessandro Ghedini <ghedo@debianorg>; Source for curl is src:curl (PTS, buildd, popcon) Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 26 Mar 2014 17:51:12 UTC Severity: grave Tags: fixed-upstr ...
Several security issues were fixed in curl ...
Two vulnerabilities have been discovered in cURL, an URL transfer library The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2014-0138 Steve Holme discovered that libcurl can in some circumstances re-use the wrong connection when asked to do transfers using other protocols than HTTP and FTP CVE-20 ...
The default configuration in cURL and libcurl 7106 before 7360 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015 ...

ICS Advisories

Hitachi Energy MSM Product
Critical Infrastructure Sectors: Energy