Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0139

Опубликовано: 15 апр. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.8

Описание

cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

РелизСтатусПримечание
devel

released

7.35.0-1ubuntu2
lucid

released

7.19.7-1ubuntu1.7
precise

released

7.22.0-3ubuntu4.8
quantal

released

7.27.0-1ubuntu1.9
saucy

released

7.32.0-1ubuntu1.4
upstream

released

7.36.0

Показывать по

EPSS

Процентиль: 79%
0.01203
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

redhat
почти 12 лет назад

cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

nvd
почти 12 лет назад

cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

debian
почти 12 лет назад

cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qso ...

github
больше 3 лет назад

cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

fstec
больше 11 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 79%
0.01203
Низкий

5.8 Medium

CVSS2