CVE-2016-9952

Description

The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted wildcard SAN in a server certificate, as demonstrated by *.com.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.005

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2016-9586,CVE-2016-9952,CVE-2016-9953 are affected in Curl For Windows 7.51.0Windows
Multiple Vulnerabilities are affected in Curl For Windows 7.51.0Windows
Vulnerabilities CVE-2016-9586,CVE-2016-9952,CVE-2016-9953 are fixed in Curl For Windows 7.52.0Windows
Improper Certificate Validation Vulnerability (CVE-2016-9952)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234