CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.
References
Link Providers
https://www.spirityenterprise.com/pentest spirity
http://advisories.mageia.org/MGASA-2015-0020.html cve-icon cve-icon
http://curl.haxx.se/docs/adv_20150108B.html cve-icon cve-icon cve-icon
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147856.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147876.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/156945.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157188.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-updates/2015-02/msg00040.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2015-1254.html cve-icon cve-icon
http://secunia.com/advisories/61925 cve-icon cve-icon
http://secunia.com/advisories/62075 cve-icon cve-icon
http://secunia.com/advisories/62361 cve-icon cve-icon
http://www.debian.org/security/2015/dsa-3122 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2015:021 cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html cve-icon cve-icon
http://www.securityfocus.com/bid/71964 cve-icon cve-icon
http://www.securitytracker.com/id/1032768 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-2474-1 cve-icon cve-icon
https://kc.mcafee.com/corporate/index?page=content&id=SB10131 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2014-8150 cve-icon
https://security.gentoo.org/glsa/201701-47 cve-icon cve-icon
https://support.apple.com/kb/HT205031 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2014-8150 cve-icon
History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.03428}

epss

{'score': 0.0215}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T13:10:50.913Z

Reserved: 2014-10-10T00:00:00

Link: CVE-2014-8150

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-01-15T15:59:06.047

Modified: 2025-04-12T10:46:40.837

Link: CVE-2014-8150

cve-icon Redhat

Severity : Moderate

Publid Date: 2015-01-08T00:00:00Z

Links: CVE-2014-8150 - Bugzilla