Asymmetric denial of service In curl
Description
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 7.85.0-1 | ||
alpine v3.14 | 7.79.1-r3 | ||
alpine v3.15 | 7.80.0-r3 | ||
alpine v3.16 | 7.83.1-r3 | ||
alpine v3.18 | 7.85.0-r0 | ||
debian 14 | 7.85.0-1 | ||
alpine v3.13 | 7.79.1-r3 | ||
alpine v3.17 | 7.85.0-r0 | ||
alpine v3.19 | 7.85.0-r0 | ||
alpine v3.20 | 7.85.0-r0 |
1-10 of 19
10
Aliases
1. 2. 3. 4. 5. 6. 7.