UBUNTU-CVE-2023-46218
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-46218
UBUNTU-CVE-2023-46218
Summary:
Details: This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.
References: https://ubuntu.com/security/CVE-2023-46218, https://curl.se/docs/CVE-2023-46218.html, https://ubuntu.com/security/notices/USN-6535-1, https://ubuntu.com/security/notices/USN-6641-1, https://www.cve.org/CVERecord?id=CVE-2023-46218
Affected packages
Package
Name: curl
Purl: pkg:deb/ubuntu/[email protected]+esm11?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
