CVE-2014-0139
published 2014-04-15CVE-2014-0139: cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common…
PriorityP427medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.20%
79.4th percentile
cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Affected
135 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | curl | < curl 7.36.0-1 (bookworm) | curl 7.36.0-1 (bookworm) |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_ubuntu6.4MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2014-04-14·CVSS 6.4
CVE-2014-0138 [MEDIUM] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Steve Holme discovered that libcurl incorrectly reused wrong connections
when using protocols other than HTTP and FTP. This could lead to the use of
unintended credentials, possibly exposing sensitive information.
(CVE-2014-0138)
Richard Moore discovered that libcurl incorrectly validated wildcard SSL
certificates that contain literal IP addresses. An attacker could possibly
exploit this to perform a machine-in-the-middle attack to view sensitive
information or alter encrypted communications. (CVE-2014-0139)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
curl: IP address wildcard certificate validation issue in libcurl
vendor_redhat·2014-03-26·CVSS 5.8
CVE-2014-0139 [MEDIUM] CWE-297 curl: IP address wildcard certificate validation issue in libcurl
curl: IP address wildcard certificate validation issue in libcurl
cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Statement: This issue did not affect the versions of curl as shipped with Red Hat Enterprise Linux 6 and 7 because it uses the NSS backend, not OpenSSL. It does affect Red Hat Enterprise Linux 5 which uses the OpenSSL backend.
Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is
Debian
CVE-2014-0139: curl - cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gsk...
vendor_debian·2014·CVSS 5.8
CVE-2014-0139 [MEDIUM] CVE-2014-0139: curl - cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gsk...
cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Scope: local
bookworm: resolved (fixed in 7.36.0-1)
bullseye: resolved (fixed in 7.36.0-1)
forky: resolved (fixed in 7.36.0-1)
sid: resolved (fixed in 7.36.0-1)
trixie: resolved (fixed in 7.36.0-1)
GHSA
GHSA-vwm2-85hg-5h4q: cURL and libcurl 7
ghsa_unreviewed·2022-05-17
CVE-2014-0139 [MEDIUM] GHSA-vwm2-85hg-5h4q: cURL and libcurl 7
cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
OSV
CVE-2014-0139: cURL and libcurl 7
osv·2014-04-15·CVSS 5.8
CVE-2014-0139 [MEDIUM] CVE-2014-0139: cURL and libcurl 7
cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0138 CVE-2014-0139 mingw32-curl: various flaws [epel-5]
bugzilla·2014-03-26·CVSS 6.4
CVE-2014-0138 [MEDIUM] CVE-2014-0138 CVE-2014-0139 mingw32-curl: various flaws [epel-5]
CVE-2014-0138 CVE-2014-0139 mingw32-curl: various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for mingw32-cur
Bugzilla
CVE-2014-0138 CVE-2014-0139 mingw-curl: various flaws [fedora-all]
bugzilla·2014-03-26·CVSS 6.4
CVE-2014-0138 [MEDIUM] CVE-2014-0138 CVE-2014-0139 mingw-curl: various flaws [fedora-all]
CVE-2014-0138 CVE-2014-0139 mingw-curl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multip
Bugzilla
CVE-2014-0139 curl: IP address wildcard certificate validation issue in libcurl
bugzilla·2014-03-21·CVSS 4.3
CVE-2014-0139 [MEDIUM] CVE-2014-0139 curl: IP address wildcard certificate validation issue in libcurl
CVE-2014-0139 curl: IP address wildcard certificate validation issue in libcurl
Daniel Stenberg reported the following vulnerability in cURL:
libcurl incorrectly validates wildcard SSL certificates containing literal
IP addresses.
RFC 2818 covers the requirements for matching Common Names (CNs) and
subjectAltNames in order to establish valid SSL connections. It first
discusses CNs that are for hostnames, and the rules for wildcards in this
case. The next paragraph in the RFC then discusses CNs that are IP
addresses:
'In some cases, the URI is specified as an IP address rather than a
hostname. In this case, the iPAddress subjectAltName must be present in the
certificate and must exactly match the IP in the URI.'
The intention of the RFC is clear in that you should not be able to use
wi
Bugzilla
CVE-2013-6484 pidgin: DoS via specially-crafted stun messages
bugzilla·2014-01-24·CVSS 5.0
CVE-2013-6484 [MEDIUM] CVE-2013-6484 pidgin: DoS via specially-crafted stun messages
CVE-2013-6484 pidgin: DoS via specially-crafted stun messages
A flaw was found in the way pidgin handled certain responses from a stun server. A remote stun server could send specially-crafted messages to pidgin causing it to crash.
Acknowledgements:
Red Hat would like to thank the Pidgin project for reporting this issue.
Discussion:
Created attachment 855926
Local copy of patch
---
External References:
http://pidgin.im/news/security/?id=79
---
Created pidgin tracking bugs for this issue:
Affects: fedora-all [bug 1059049]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2014:0139 https://rhn.redhat.com/errata/RHSA-2014-0139.html
---
pidgin-2.10.9-1.fc20 has been pushed to the Fedora 20 stable repositor
Bugzilla
CVE-2013-6478 pidgin: DoS when rendering long URLs
bugzilla·2014-01-23·CVSS 4.3
CVE-2013-6478 [MEDIUM] CVE-2013-6478 pidgin: DoS when rendering long URLs
CVE-2013-6478 pidgin: DoS when rendering long URLs
It was found that pidgin crashed when a mouse pointer was hovered over a long URL. libX11 forcefully exits when Pidgin tries to create an exceptionally wide tooltip window.
Acknowledgements:
Red Hat would like to thank the Pidgin project for reporting this issue.
Discussion:
Created attachment 855919
Local copy of patch
---
External References:
http://pidgin.im/news/security/?id=72
---
Created pidgin tracking bugs for this issue:
Affects: fedora-all [bug 1059049]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2014:0139 https://rhn.redhat.com/errata/RHSA-2014-0139.html
---
pidgin-2.10.9-1.fc20 has been pushed to the Fedora 20 stable repository. If pro
Bugzilla
CVE-2013-6481 pidgin: DoS caused due to OOB read in Yahoo protocol plugin
bugzilla·2014-01-23·CVSS 5.0
CVE-2013-6481 [MEDIUM] CVE-2013-6481 pidgin: DoS caused due to OOB read in Yahoo protocol plugin
CVE-2013-6481 pidgin: DoS caused due to OOB read in Yahoo protocol plugin
The Yahoo! protocol plugin of pidgin failed to validate a length field before trying to read from a buffer, which could result in reading past the end of the buffer which could cause a crash.
Acknowledgements:
Red Hat would like to thank the Pidgin project for reporting this issue. Upstream acknowledges Daniel Atallah as the original reporter of this issue.
Discussion:
Created attachment 855921
Local copy of the patch
---
External References:
http://pidgin.im/news/security/?id=74
---
Created pidgin tracking bugs for this issue:
Affects: fedora-all [bug 1059049]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2014:0139 https://rhn.
Bugzilla
CVE-2013-6479 pidgin: DoS when parsing certain HTTP response headers
bugzilla·2014-01-23·CVSS 5.0
CVE-2013-6479 [MEDIUM] CVE-2013-6479 pidgin: DoS when parsing certain HTTP response headers
CVE-2013-6479 pidgin: DoS when parsing certain HTTP response headers
A flaw was found in the way pidgin certain HTTP response headers. A malicious server or man-in-the-middle could send a malformed HTTP response that could lead to a crash.
Acknowledgements:
Red Hat would like to thank the Pidgin project for reporting this issue. Upstream acknowledges Jacob Appelbaum of the Tor Project as the original reporter of this issue.
Discussion:
External References:
http://pidgin.im/news/security/?id=73
---
Created pidgin tracking bugs for this issue:
Affects: fedora-all [bug 1059049]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2014:0139 https://rhn.redhat.com/errata/RHSA-2014-0139.html
---
pidgin-2.10.9-1.fc
Bugzilla
CVE-2013-6477 pidgin: DoS when handling timestamps in the XMPP plugin
bugzilla·2014-01-22·CVSS 5.0
CVE-2013-6477 [MEDIUM] CVE-2013-6477 pidgin: DoS when handling timestamps in the XMPP plugin
CVE-2013-6477 pidgin: DoS when handling timestamps in the XMPP plugin
A Denial-of-service flaw was found in the way the XMPP protocol plugin of pidgin handled messages with invalid timestamps. A remote XMPP user can trigger a crash on some systems by sending a
message with a timestamp in the distant future.
Acknowledgements:
Red Hat would like to thank the Pidgin project for reporting this issue. Upstream acknowledges Jaime Breva Ribes as the original reporter of this issue.
Discussion:
External References:
http://pidgin.im/news/security/?id=71
---
Created pidgin tracking bugs for this issue:
Affects: fedora-all [bug 1059049]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2014:0139 https://rhn.redhat.com
http://advisories.mageia.org/MGASA-2015-0165.htmlhttp://curl.haxx.se/docs/adv_20140326B.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00042.htmlhttp://secunia.com/advisories/57836http://secunia.com/advisories/57966http://secunia.com/advisories/57968http://secunia.com/advisories/58615http://secunia.com/advisories/59458http://www-01.ibm.com/support/docview.wss?uid=swg21675820http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862http://www.debian.org/security/2014/dsa-2902http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/http://www.mandriva.com/security/advisories?name=MDVSA-2015:213http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.ubuntu.com/usn/USN-2167-1http://advisories.mageia.org/MGASA-2015-0165.htmlhttp://curl.haxx.se/docs/adv_20140326B.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00042.htmlhttp://secunia.com/advisories/57836http://secunia.com/advisories/57966http://secunia.com/advisories/57968http://secunia.com/advisories/58615http://secunia.com/advisories/59458http://www-01.ibm.com/support/docview.wss?uid=swg21675820http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862http://www.debian.org/security/2014/dsa-2902http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/http://www.mandriva.com/security/advisories?name=MDVSA-2015:213http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.ubuntu.com/usn/USN-2167-1
2014-04-15
Published