Логотип exploitDog
bind:CVE-2024-2466
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-2466

Количество 7

Количество 7

ubuntu логотип

CVE-2024-2466

почти 2 года назад

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2024-2466

почти 2 года назад

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-2466

почти 2 года назад

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-2466

больше 1 года назад

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-2466

почти 2 года назад

libcurl did not check the server certificate of TLS connections done t ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9xr6-qf7m-2jv5

почти 2 года назад

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2024-02736

почти 2 года назад

Уязвимость реализации протоколов TLS (HTTPS, FTPS, IMAPS, POPS3, SMTPS и т.д.) утилиты командной строки cURL, позволяющая нарушителю проводить спуфинг-атаки

CVSS3: 5.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-2466

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

CVSS3: 6.5
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-2466

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

CVSS3: 5.3
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-2466

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

CVSS3: 6.5
0%
Низкий
почти 2 года назад
msrc логотип
CVSS3: 6.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-2466

libcurl did not check the server certificate of TLS connections done t ...

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-9xr6-qf7m-2jv5

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

CVSS3: 6.5
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-02736

Уязвимость реализации протоколов TLS (HTTPS, FTPS, IMAPS, POPS3, SMTPS и т.д.) утилиты командной строки cURL, позволяющая нарушителю проводить спуфинг-атаки

CVSS3: 5.6
0%
Низкий
почти 2 года назад

Уязвимостей на страницу