ALPINE-CVE-2014-0138 PUBLISHED

The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.

Affected Products

VendorProductVersions
Alpine:v3.7curl0, 7.35.0-r0, 7.34.0-r1
Alpine:v3.16curl7.21.0-r0, 7.35.0-r0, 7.34.0-r1
Alpine:v3.6curl7.21.7-r0, 7.35.0-r0, 7.34.0-r1
Alpine:v3.11curl7.35.0-r0, 7.19.2-r1, 7.19.4-r0
Alpine:v3.23curl7.19.4-r0, 7.35.0-r0, 7.34.0-r1
Alpine:v3.14curl0, 7.34.0-r1, 7.34.0-r0
Alpine:v3.17curl7.21.4-r0, 7.19.2-r0, 7.19.2-r1
Alpine:v3.4curl0, 7.34.0-r1, 7.34.0-r0
Alpine:v3.22curl7.21.7-r2, 7.21.1-r0, 0
Alpine:v3.13curl7.19.2-r0, 7.19.2-r1, 7.19.4-r0
Alpine:v3.10curl7.20.1-r0, 7.19.2-r0, 7.19.2-r1
Alpine:v3.15curl0, 7.19.2-r0, 7.19.4-r0
Alpine:v3.18curl7.35.0-r0, 7.19.5-r0, 7.19.6-r0
Alpine:v3.19curl0, 7.19.2-r0, 7.19.2-r1
Alpine:v3.9curl7.35.0-r0, 7.35.0-r0, 7.34.0-r1
Alpine:v3.8curl7.19.2-r1, 7.35.0-r0, 7.34.0-r1
Alpine:v3.21curl7.33.0-r1, 7.35.0-r0, 7.34.0-r1
Alpine:v3.5curl0, 7.35.0-r0, 7.19.2-r0
Alpine:v3.20curl7.35.0-r0, 0, 7.19.2-r0
Alpine:v3.12curl7.19.2-r1, 7.19.2-r0, 7.35.0-r0

Timeline

References

Open in Interactive Console →