curl and libcurl 7.27.0 through 7.35.0, when using the SecureTransport/Darwinssl backend, as used in in Apple OS X 10.9.x before 10.9.2, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:03
Type | Values Removed | Values Added |
---|---|---|
References | () http://curl.haxx.se/docs/adv_20140326C.html - | |
References | () http://secunia.com/advisories/57836 - | |
References | () http://secunia.com/advisories/57966 - | |
References | () http://secunia.com/advisories/57968 - | |
References | () http://support.apple.com/kb/HT6150 - Vendor Advisory | |
References | () http://twitter.com/agl__/statuses/437029812046422016 - | |
References | () http://twitter.com/okoeroo/statuses/437272014043496449 - Exploit | |
References | () http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/ - | |
References | () http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/ - | |
References | () http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/ - | |
References | () https://gist.github.com/rmoriz/fb2b0a6a0ce10550ab73 - Exploit |
Information
Published : 2014-02-27 01:55
Updated : 2024-11-21 02:03
NVD link : CVE-2014-1263
Mitre link : CVE-2014-1263
CVE.ORG link : CVE-2014-1263
JSON object : View
Products Affected
apple
- mac_os_x
CWE
CWE-310
Cryptographic Issues