CVE-2013-6422

Description

The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

Risk Information

Base Score
7.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.253

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Curl For Windows 7.21.6Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.21.4Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.21.5Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.21.7Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.22.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.23.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.23.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.24.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.25.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.26.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.27.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.28.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.28.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.29.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.30.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.31.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.32.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.33.0Windows
Vulnerabilities CVE-2013-6422 are fixed in Curl For Windows 7.34.0Windows
Improper Input Validation Vulnerability (CVE-2013-6422)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234