CVE-2015-3153

CVSS 5.0 - MEDIUM
Description

The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.

Affected Products
12
Vendor Product Version
oracle enterprise_manager_ops_center All versions
oracle enterprise_manager_ops_center 12.2.0
oracle enterprise_manager_ops_center 12.2.1
oracle enterprise_manager_ops_center 12.3.0
haxx curl All versions
haxx libcurl All versions
canonical ubuntu_linux 12.04
canonical ubuntu_linux 14.04
canonical ubuntu_linux 14.10
canonical ubuntu_linux 15.1
apple mac_os_x 10.10.4
debian debian_linux 8.0
Weakness Types
CWE-200
CVE Information
CVE ID:
CVE-2015-3153
Published:
2015-05-01
Modified:
2026-05-06
CVSS Score:
5.0
Severity:
MEDIUM
Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
Affected Vendors
oracle haxx canonical apple debian
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL