Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-2379
HistoryMar 27, 2024 - 12:00 a.m.

CVE-2024-2379

2024-03-2700:00:00
ubuntu.com
ubuntu.com
15
cve-2024-2379
libcurl
certificate verification
quic connection
wolfssl
cipher error
low severity
ubuntu
8.6.0

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.8%

libcurl skips the certificate verification for a QUIC connection under
certain conditions, when built to use wolfSSL. If told to use an
unknown/bad cipher or curve, the error path accidentally skips the
verification and returns OK, thus ignoring any certificate problems.

Notes

Author Note
Priority reason: Upstream developers consider this a low severity issue
mdeslaur Ubuntu package does not use the wolfSSL backend. Only affects 8.6.0.

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.8%