CVE-2014-2522

Description

curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS backend, does not verify that the server hostname matches a domain name in the subjects Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.

Risk Information

Base Score
5.9
MODERATE
Vector
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.292

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2014-0138,CVE-2014-0139,CVE-2014-2522 are affected in Curl For Windows 7.35.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.27.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.28.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.28.1Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.29.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.30.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.31.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.32.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.33.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.34.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.35.0Windows
Vulnerabilities CVE-2014-2522,CVE-2014-1263,CVE-2014-0139,CVE-2014-0138 are fixed in Curl For Windows 7.36.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234