CVE-2014-2522 Information
Description
curl and libcurl 7.27.0 through 7.35.0 when running on Windows and using the SChannel/Winssl TLS backend does not verify that the server hostname matches a domain name in the subject’s Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.
Reference
http://curl.haxx.se/docs/adv_20140326D.html http://curl.haxx.se/docs/adv_20140326D.html http://seclists.org/oss-sec/2014/q1/585 [oss-security] 20140317 CVE request: flaw in curl’s Windows SSL backend http://seclists.org/oss-sec/2014/q1/586 [oss-security] 20140317 Re: CVE request: flaw in curl’s Windows SSL backend http://secunia.com/advisories/57836 http://secunia.com/advisories/57966 http://secunia.com/advisories/57968 http://secunia.com/advisories/59458 http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/ http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/ http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/ http://www.securityfocus.com/bid/66296 http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862 curl and libcurl 7.27.0 through 7.35.0 when running on Windows and using the SChannel/Winssl TLS backend does not verify that the server hostname matches a domain name in the subject’s Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate. cpe:2.3:a:haxx:curl:7.27.0:::::::* cpe:2.3:a:haxx:curl:7.28.0:::::::* cpe:2.3:a:haxx:curl:7.28.1:::::::* cpe:2.3:a:haxx:curl:7.29.0:::::::* cpe:2.3:a:haxx:curl:7.30.0:::::::* cpe:2.3:a:haxx:curl:7.31.0:::::::* cpe:2.3:a:haxx:curl:7.32.0:::::::* cpe:2.3:a:haxx:curl:7.33.0:::::::* cpe:2.3:a:haxx:curl:7.34.0:::::::* cpe:2.3:a:haxx:curl:7.35.0:::::::* cpe:2.3:a:haxx:libcurl:7.27.0:::::::* cpe:2.3:a:haxx:libcurl:7.28.0:::::::* cpe:2.3:a:haxx:libcurl:7.28.1:::::::* cpe:2.3:a:haxx:libcurl:7.29.0:::::::* cpe:2.3:a:haxx:libcurl:7.30.0:::::::* cpe:2.3:a:haxx:libcurl:7.31.0:::::::* cpe:2.3:a:haxx:libcurl:7.32.0:::::::* cpe:2.3:a:haxx:libcurl:7.33.0:::::::* cpe:2.3:a:haxx:libcurl:7.34.0:::::::* cpe:2.3:a:haxx:libcurl:7.35.0:::::::* cpe:2.3:a:haxx:libcurl:7.36.0:::::::*
Share on: