Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-6422

Опубликовано: 23 дек. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4

Описание

The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

РелизСтатусПримечание
devel

not-affected

7.34.0-1ubuntu1
lucid

not-affected

7.19.7-1ubuntu1.3
precise

released

7.22.0-3ubuntu4.6
quantal

released

7.27.0-1ubuntu1.7
raring

released

7.29.0-1ubuntu3.4
saucy

released

7.32.0-1ubuntu1.2
upstream

pending

7.34.0-1

Показывать по

EPSS

Процентиль: 48%
0.00253
Низкий

4 Medium

CVSS2

Связанные уязвимости

redhat
около 12 лет назад

The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

nvd
около 12 лет назад

The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

debian
около 12 лет назад

The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling di ...

github
больше 3 лет назад

The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

fstec
около 12 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 48%
0.00253
Низкий

4 Medium

CVSS2