CVE-2016-3739

MEDIUM

curl < 7.49.0 - Server Spoofing via Arbitrary Valid Certificate

Title source: llm
STIX 2.1

Description

The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7.49.0, when using SSLv3 or making a TLS connection to a URL that uses a numerical IP address, allow remote attackers to spoof servers via an arbitrary valid certificate.

Scores

CVSS v3 5.3
EPSS 0.0107
EPSS Percentile 78.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-20
Status published
Products (37)
haxx/curl 7.21.0
haxx/curl 7.21.1
haxx/curl 7.21.2
haxx/curl 7.21.3
haxx/curl 7.21.4
haxx/curl 7.21.5
haxx/curl 7.21.6
haxx/curl 7.21.7
haxx/curl 7.22.0
haxx/curl 7.23.0
... and 27 more
Published May 20, 2016
Tracked Since Feb 18, 2026