Lucene search

K
cve[email protected]CVE-2013-6422
HistoryDec 23, 2013 - 10:55 p.m.

CVE-2013-6422

2013-12-2322:55:02
CWE-20
web.nvd.nist.gov
45
cve-2013-6422
gnutls
libcurl
ssl verification
mitm attack
nvd

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

6.8 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

64.7%

The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

Affected configurations

NVD
Node
debiandebian_linuxMatch7.0
Node
canonicalubuntu_linuxMatch12.04-lts
OR
canonicalubuntu_linuxMatch12.10
OR
canonicalubuntu_linuxMatch13.04
OR
canonicalubuntu_linuxMatch13.10
Node
haxxlibcurlMatch7.21.4
OR
haxxlibcurlMatch7.21.5
OR
haxxlibcurlMatch7.21.6
OR
haxxlibcurlMatch7.21.7
OR
haxxlibcurlMatch7.22.0
OR
haxxlibcurlMatch7.23.0
OR
haxxlibcurlMatch7.23.1
OR
haxxlibcurlMatch7.24.0
OR
haxxlibcurlMatch7.25.0
OR
haxxlibcurlMatch7.26.0
OR
haxxlibcurlMatch7.27.0
OR
haxxlibcurlMatch7.28.0
OR
haxxlibcurlMatch7.28.1
OR
haxxlibcurlMatch7.29.0
OR
haxxlibcurlMatch7.30.0
OR
haxxlibcurlMatch7.31.0
OR
haxxlibcurlMatch7.32.0
OR
haxxlibcurlMatch7.33.0

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

6.8 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

64.7%