Back

MEDIUM

curl: certificate check bypass when built with DarwinSSL as TLS backend

Published Jan 15, 2015

Description

The darwinssl_connect_step1 function in lib/vtls/curl_darwinssl.c in libcurl 7.31.0 through 7.39.0, when using the DarwinSSL (aka SecureTransport) back-end for TLS, does not check if a cached TLS session validated the certificate when reusing the session, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of curl as shipped with Red Hat Enterprise Linux 5, 6 and 7 as they do no use DarwinSSL library as TLS backend.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 15, 2015
Updated Aug 6, 2024
Reserved Oct 10, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jan 8, 2015