commit | 2eb8dcf26cb37f09cffe26909a646e702dbcab66 | [log] [tgz] |
---|---|---|
author | YAMADA Yasuharu <yasuharu.yamada@access-company.com> | Thu Apr 11 00:17:15 2013 +0200 |
committer | Daniel Stenberg <daniel@haxx.se> | Thu Apr 11 23:52:12 2013 +0200 |
tree | bb1b22e9302afec2abe6e795533b9860ab691298 | |
parent | 96ffe645fd2494f14780f7c105fcfeeb8ca7d94f [diff] |
cookie: fix tailmatching to prevent cross-domain leakage Cookies set for 'example.com' could accidentaly also be sent by libcurl to the 'bexample.com' (ie with a prefix to the first domain name). This is a security vulnerabilty, CVE-2013-1944. Bug: http://curl.haxx.se/docs/adv_20130412.html