CVE-2014-8151

The darwinssl_connect_step1 function in lib/vtls/curl_darwinssl.c in libcurl 7.31.0 through 7.39.0, when using the DarwinSSL (aka SecureTransport) back-end for TLS, does not check if a cached TLS session validated the certificate when reusing the session, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
Configurations

Configuration 1 (hide)

cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:haxx:libcurl:7.31.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.32.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.33.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.34.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.35.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.36.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.37.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.37.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.38.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.39:*:*:*:*:*:*:*

History

21 Nov 2024, 02:18

Type Values Removed Values Added
References () http://curl.haxx.se/docs/adv_20150108A.html - Vendor Advisory () http://curl.haxx.se/docs/adv_20150108A.html - Vendor Advisory
References () http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743 - () http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743 -
References () http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html - () http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html -
References () http://secunia.com/advisories/61925 - () http://secunia.com/advisories/61925 -
References () https://security.gentoo.org/glsa/201701-47 - () https://security.gentoo.org/glsa/201701-47 -
References () https://support.apple.com/kb/HT205031 - () https://support.apple.com/kb/HT205031 -

Information

Published : 2015-01-15 15:59

Updated : 2024-11-21 02:18


NVD link : CVE-2014-8151

Mitre link : CVE-2014-8151

CVE.ORG link : CVE-2014-8151


JSON object : View

Products Affected

apple

  • mac_os_x

haxx

  • libcurl