CVE-2014-0139

Description

cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subjects Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.203

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2014-0138,CVE-2014-0139,CVE-2014-2522 are affected in Curl For Windows 7.35.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.21.6Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.21.4Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.21.5Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.21.7Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.22.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.23.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.23.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.24.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.25.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.26.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.27.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.28.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.28.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.29.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.30.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.31.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.32.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.33.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.17.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.18.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.18.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.18.2Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.19.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.19.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.19.2Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.19.3Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.19.4Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.19.5Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.19.6Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.19.7Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.20.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.20.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.21.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.21.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.21.2Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.21.3Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.34.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.35.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.10.6Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.10.7Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.10.8Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.11.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.11.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.11.2Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.12.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.12.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.12.2Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.12.3Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.13.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.13.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.13.2Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.14.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.14.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.15.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.15.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.15.2Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.15.3Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.15.4Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.15.5Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.16.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.16.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.16.2Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.16.3Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.16.4Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.17.0Windows
Vulnerabilities CVE-2014-2522,CVE-2014-1263,CVE-2014-0139,CVE-2014-0138 are fixed in Curl For Windows 7.36.0Windows
curl security update(DSA-3455-1) curl_7.38.0-4+deb8u3_i386.debLinux
CVE-2014-0139NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234