CVE-2014-1263

Apple macOS X < 10.9.2 - Certificate Hostname Validation Bypass via Numerical IP Address

Title source: llm
STIX 2.1

Description

curl and libcurl 7.27.0 through 7.35.0, when using the SecureTransport/Darwinssl backend, as used in in Apple OS X 10.9.x before 10.9.2, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.

References (11)

Core 11
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57836
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6150
Various Sources x_refsource_misc
http://twitter.com/agl__/statuses/437029812046422016
Various Sources x_refsource_confirm
http://curl.haxx.se/docs/adv_20140326C.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57968
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57966

Scores

EPSS 0.0286
EPSS Percentile 85.3%

Details

CWE
CWE-310
Status published
Products (2)
apple/mac_os_x 10.9
apple/mac_os_x < 10.9.1
Published Feb 27, 2014
Tracked Since Feb 18, 2026