CVE-2013-4545
Publication date 23 November 2013
Last updated 24 July 2024
Ubuntu priority
cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST) when the digital signature verification (CURLOPT_SSL_VERIFYPEER) is disabled, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Status
Package | Ubuntu Release | Status |
---|---|---|
curl | ||
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2048-1
- curl vulnerability
- 5 December 2013