Lucene search

K
cvelistRedhatCVELIST:CVE-2013-4545
HistoryNov 23, 2013 - 11:00 a.m.

CVE-2013-4545

2013-11-2311:00:00
redhat
www.cve.org
1

6.4 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

59.2%

cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST) when the digital signature verification (CURLOPT_SSL_VERIFYPEER) is disabled, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.