CVE-2007-3564Libcurl vulnerability

7 documents7 sources
Severity
7.5HIGHNVD
EPSS
0.6%
top 29.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 18
Latest updateMay 1

Description

libcurl 7.14.0 through 7.16.3, when built with GnuTLS support, does not check SSL/TLS certificate expiration or activation dates, which allows remote attackers to bypass certain access restrictions.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDlibcurl/libcurl7 versions+6
Debianhaxx/curl< 7.16.4-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-83vp-5vg4-r3g7: libcurl 72022-05-01
CVEList
CVE-2007-3564: libcurl 72007-07-18
OSV
CVE-2007-3564: libcurl 72007-07-18

📋Vendor Advisories

3
Ubuntu
curl vulnerability2007-07-17
Debian
CVE-2007-3564: curl - libcurl 7.14.0 through 7.16.3, when built with GnuTLS support, does not check SS...2007
Red Hat
CVE-2007-3564: libcurl 7
CVE-2007-3564 — Libcurl vulnerability | cvebase