CVE-2013-6422
published 2013-12-23CVE-2013-6422: The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the…
PriorityP418medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
2.76%
84.4th percentile
The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | curl | < curl 7.34.0-1 (bookworm) | curl 7.34.0-1 (bookworm) |
| debian | debian_linux | — | — |
| haxx | curl | >= 0 < 7.34.0-1 | 7.34.0-1 |
| haxx | curl | >= 0 < 7.34.0-1 | 7.34.0-1 |
| haxx | curl | >= 0 < 7.34.0-1 | 7.34.0-1 |
| haxx | curl | >= 0 < 7.34.0-1 | 7.34.0-1 |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fw5f-w62r-p5ww: The GnuTLS backend in libcurl 7
ghsa_unreviewed·2022-05-17
CVE-2013-6422 [MEDIUM] CWE-20 GHSA-fw5f-w62r-p5ww: The GnuTLS backend in libcurl 7
The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
OSV
CVE-2013-6422: The GnuTLS backend in libcurl 7
osv·2013-12-23·CVSS 4.0
CVE-2013-6422 [MEDIUM] CVE-2013-6422: The GnuTLS backend in libcurl 7
The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
Ubuntu
curl vulnerability
vendor_ubuntu·2013-12-18
CVE-2013-6422 curl vulnerability
Title: curl vulnerability
Summary: Fraudulent security certificates could allow sensitive information to be
exposed when accessing the Internet.
Marc Deslauriers discovered that libcurl incorrectly verified CN and SAN
name fields when digital signature verification was disabled in the GnuTLS
backend. When libcurl is being used in this uncommon way by specific
applications, an attacker could exploit this to perform a machine-in-the-middle
attack to view sensitive information or alter encrypted communications.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
curl: TLS/SSL certificate name check disabled with peer verification when using GnuTLS
vendor_redhat·2013-12-17·CVSS 4.0
CVE-2013-6422 [MEDIUM] curl: TLS/SSL certificate name check disabled with peer verification when using GnuTLS
curl: TLS/SSL certificate name check disabled with peer verification when using GnuTLS
The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
Statement: Not vulnerable. This issue did not affect the versions of curl as shipped with Red Hat Enterprise Linux 5 and 6.
Package: curl (Red Hat Enterprise Linux 5) - Not affected
Package: curl (Red Hat Enterprise Linux 6) - Not affected
Package: curl (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-6422: curl - The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital sign...
vendor_debian·2013·CVSS 4.0
CVE-2013-6422 [MEDIUM] CVE-2013-6422: curl - The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital sign...
The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
Scope: local
bookworm: resolved (fixed in 7.34.0-1)
bullseye: resolved (fixed in 7.34.0-1)
forky: resolved (fixed in 7.34.0-1)
sid: resolved (fixed in 7.34.0-1)
trixie: resolved (fixed in 7.34.0-1)
No detection rules found.
No public exploits indexed.
http://curl.haxx.se/docs/adv_20131217.htmlhttp://www.debian.org/security/2013/dsa-2824http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.ubuntu.com/usn/USN-2058-1https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322http://curl.haxx.se/docs/adv_20131217.htmlhttp://www.debian.org/security/2013/dsa-2824http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.ubuntu.com/usn/USN-2058-1https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322
2013-12-23
Published