Hide Forgot
A security flaw was found in the way the library of cURL, an utility for retrieval of files from remote servers, performed match of cookie domain names when making a decision if (previously stored cookies) should be sent to particular domain. Due to a bug in match function implementation, (formerly) the decision / match succeeded also in cases, where just suffix / certain part of the domain name matched the domain name, the current request originated from. A remote attacker could use this flaw to possibly hijack the user session of the victim by submitting a request containing a specially-crafted domain name. References: [1] http://thread.gmane.org/gmane.comp.web.curl.library/38986 Acknowledgements: Red Hat would like to thank the cURL project for reporting this issue. Upstream acknowledges YAMADA Yasuharu as the original reporter.
This issue affects the versions of the curl package, as shipped with Red Hat Enterprise Linux 5 and 6. -- This issue affects the versions of the curl package, as shipped with Fedora release of 17 and 18.
The CVE identifier of CVE-2013-1944 has been assigned to this issue.
Proposed upstream patch is available at: http://curl.haxx.se/curl-tailmatch.patch
Created attachment 734032 [details] Local copy of proposed upstream patch
External References: http://curl.haxx.se/docs/adv_20130412.html
Created curl tracking bugs for this issue Affects: fedora-all [bug 951417]
Relevant upstream patch: https://github.com/bagder/curl/commit/2eb8dcf26cb37f09cffe26909a646e702dbcab66 Related test suite commits: https://github.com/bagder/curl/commit/5c5e1a1cd206ad8feadaa83a37d0326ba45cf45d https://github.com/bagder/curl/commit/11dee0bfae702c07b510dce05a55d1b8144fbbcb
curl-7.27.0-8.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.
curl-7.29.0-5.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Via RHSA-2013:0771 https://rhn.redhat.com/errata/RHSA-2013-0771.html
curl-7.29.0-6.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
curl-7.27.0-9.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.