CVE-2014-0139
Publication date 27 March 2014
Last updated 24 July 2024
Ubuntu priority
cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Status
Package | Ubuntu Release | Status |
---|---|---|
curl | ||
Patch details
Package | Patch details |
---|---|
curl |
|
References
Related Ubuntu Security Notices (USN)
- USN-2167-1
- curl vulnerabilities
- 14 April 2014