cbcvebase.
CVE-2013-6422
published 2013-12-23

CVE-2013-6422: The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the…

PriorityP418medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
2.76%
84.4th percentile
The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiancurl< curl 7.34.0-1 (bookworm)curl 7.34.0-1 (bookworm)
debiandebian_linux
haxxcurl>= 0 < 7.34.0-17.34.0-1
haxxcurl>= 0 < 7.34.0-17.34.0-1
haxxcurl>= 0 < 7.34.0-17.34.0-1
haxxcurl>= 0 < 7.34.0-17.34.0-1
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.