CURL-CVE-2013-1944

    Dashboard / Vulnerabilities / CURL-CVE-2013-1944

    CURL-CVE-2013-1944

    Published: 12 Apr 2013Last Modified: 27 May 2026
    Aliases:

    Summary: cookie domain tailmatch

    Details: libcurl is vulnerable to a cookie leak vulnerability when doing requests across domains with matching tails. When communicating over HTTP(S) and having libcurl's cookie engine enabled, libcurl stores and holds cookies for use when subsequent requests are done to hosts and paths that match those kept cookies. Due to a bug in the tailmatching function, libcurl could wrongly send cookies meant for the domain 'ample.com' when communicating with 'example.com'. This vulnerability can be used to hijack sessions in targeted attacks since registering domains using a known domain's name as an ending is trivial. Both curl the command line tool and applications using the libcurl library are vulnerable.

    References:

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 4.7
    Fixed -7.30.0

    Affected versions

    7.29.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High