CVE-2018-6651 Information
Description
In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07 as used in Parsec before 140-3 insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions. In Parsec this means full control over the victim’s computer.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://gist.github.com/Zenexer/ac7601c0e367d876353137e5099b18a7 https://github.com/chrisd1100/uncurl/commit/448cd13e7b18c83855d706c564341ddd1e38e769 https://github.com/chrisd1100/uncurl/commit/448cd13e7b18c83855d706c564341ddd1e38e769 https://github.com/chrisd1100/uncurl/releases/tag/0.07 https://github.com/chrisd1100/uncurl/releases/tag/0.07 In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07 as used in Parsec before 140-3 insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions. In Parsec this means full control over the victim’s computer. cpe:2.3:a:uncurl_project:uncurl::::::::
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: