CVE-2013-6422 - CERT CVE
ID CVE-2013-6422
Sažetak The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
Reference
CVSS
Base: 4.0
Impact: 4.9
Exploitability:4.9
Pristup
VektorSloženostAutentikacija
NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL NONE
CVSS vektor AV:N/AC:H/Au:N/C:P/I:P/A:N
Zadnje važnije ažuriranje 07-04-2016 - 20:55
Objavljeno 23-12-2013 - 22:55