]> code.ossystems Code Review - openembedded-core.git/commit
curl: Security Advisory - curl - CVE-2014-3613
authorChong Lu <Chong.Lu@windriver.com>
Fri, 24 Oct 2014 08:26:41 +0000 (16:26 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 5 Nov 2014 23:26:57 +0000 (23:26 +0000)
commitdbbda31ca0a29c930f3078635ae7c5a41d933b58
tree56dae75c98b7794e07d8bbf968853eab69dccca0
parent606793e7b5c129654f317e5bec9ed7f083d3383d
curl: Security Advisory - curl - CVE-2014-3613

By not detecting and rejecting domain names for partial literal IP addresses
properly when parsing received HTTP cookies, libcurl can be fooled to both
sending cookies to wrong sites and into allowing arbitrary sites to set cookies
for others.

(From OE-Core rev: 985ef933208da1dd1f17645613ce08e6ad27e2c1)

Signed-off-by: Chong Lu <Chong.Lu@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Conflicts:
meta/recipes-support/curl/curl_7.35.0.bb
meta/recipes-support/curl/curl/CVE-2014-3613.patch [new file with mode: 0644]
meta/recipes-support/curl/curl_7.35.0.bb