CURL/libcURL SSL certificate verification Security Restriction Bypass Vulnerability
Release date:
Updated on:
Affected Systems:
CURL
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66296
CVE (CAN) ID: CVE-2014-2522
CURL is a command line FILE transmission tool that supports FTP, FTPS, HTTP, HTTPS, GOPHER, TELNET, DICT, FILE, and LDAP.
CURL/libcURL has a security vulnerability in server certificate verification. Successful exploitation can cause man-in-the-middle attacks or server spoofing.
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
CURL
----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://curl.haxx.se/