Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20511
HistoryJun 10, 2019 - 5:39 a.m.

Man-in-the-Middle (MitM)

2019-06-1005:39:48
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.002 Low

EPSS

Percentile

57.0%

libcurl.so is vulnerable to man-in-the-middle attacks. The library recognizes a wildcard IP address in the subject’s Common Name (CN) field of an X.509 certificate. This allows a remote attacker to spoof SSL servers using malicious certifacte issued by a legitimate CA and perform a man-in-the-middle attack against the server.

CPENameOperatorVersion
libcurl.soeq4.3.0
libcurl.soeq4.3.0

References