Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20510
HistoryJun 10, 2019 - 5:22 a.m.

MAN-IN-THE-MIDDLE

2019-06-1005:22:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3

0.008 Low

EPSS

Percentile

81.1%

libcurl.so is vulnerable to man-in-the-middle attack. A lack of validation of the TLS certificate and hostname in the mbed_connect_step1 function in lib/vtls/mbedtls.c and polarssl_connect_step1 function in lib/vtls/polarssl.c allows a remote attacker to spoof servers and perform man-in-the-middle attacks against the target server.