cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST) when the digital signature verification (CURLOPT_SSL_VERIFYPEER) is disabled, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2013-11-23 11:55
Updated : 2025-04-11 00:51
NVD link : CVE-2013-4545
Mitre link : CVE-2013-4545
CVE.ORG link : CVE-2013-4545
JSON object : View
Products Affected
haxx
- libcurl
- curl
CWE
CWE-310
Cryptographic Issues