Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-4947

Опубликовано: 28 мая 2025
Источник: debian

Описание

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed8.14.0-1package
curlnot-affectedbookwormpackage
curlnot-affectedbullseyepackage

Примечания

  • https://curl.se/docs/CVE-2025-4947.html

  • Introduced by: https://github.com/curl/curl/commit/4c46e277b2a0c0489de0e0fcb91f315c62f0369c (curl-8_8_0)

  • Fixed by: https://github.com/curl/curl/commit/a85f1df4803bbd272905c9e712537b41afeafbd3 (curl-8_14_0)

  • curl in Debian not built with wolfSSL support

Связанные уязвимости

CVSS3: 6.5
ubuntu
22 дня назад

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

CVSS3: 6.5
redhat
22 дня назад

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

CVSS3: 6.5
nvd
22 дня назад

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

CVSS3: 6.5
github
22 дня назад

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.