CVE-2014-2522

curl and libcurl <7.35.0 - SSL/TLS Man-in-the-Middle

Title source: llm
STIX 2.1

Description

curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS backend, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.

References (12)

Core 12
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57836
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/66296
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59458
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2014/q1/586
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57968
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2014/q1/585
Patch, Vendor Advisory x_refsource_confirm
http://curl.haxx.se/docs/adv_20140326D.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57966

Scores

EPSS 0.0024
EPSS Percentile 47.8%

Details

CWE
CWE-20
Status published
Products (21)
haxx/curl 7.27.0
haxx/curl 7.28.0
haxx/curl 7.28.1
haxx/curl 7.29.0
haxx/curl 7.30.0
haxx/curl 7.31.0
haxx/curl 7.32.0
haxx/curl 7.33.0
haxx/curl 7.34.0
haxx/curl 7.35.0
... and 11 more
Published Apr 18, 2014
Tracked Since Feb 18, 2026