CVE-2014-0138 describes a vulnerability in cURL and libcurl versions prior to 7.36.0, where default configurations improperly reuse SCP, SFTP, POP3/S, IMAP/S, SMTP/S, and LDAP/S connections. This flaw could allow attackers to connect as other users due to context-dependent request handling, affecting products like Debian curl and libcurl. With a CVSS score of 6.4, this vulnerability is of medium severity, allowing for network-based attacks with low complexity that could lead to unauthorized information disclosure and modification. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, and it has received minimal community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.10.6CPE matchmatch criteria | cpe:2.3:a:haxx:curl:7.10.6:*:*:*:*:*:*:* | ||
7.10.7CPE matchmatch criteria | cpe:2.3:a:haxx:curl:7.10.7:*:*:*:*:*:*:* | ||
7.10.8CPE matchmatch criteria | cpe:2.3:a:haxx:curl:7.10.8:*:*:*:*:*:*:* | ||
7.11.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:7.11.0:*:*:*:*:*:*:* | ||
7.11.1CPE matchmatch criteria | cpe:2.3:a:haxx:curl:7.11.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.