| ID | 
        
          CVE-2013-6422
         | 
      
      
          | Sažetak | 
        The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks. | 
      
      
          | Reference | 
        
          
         | 
      
      
        | CVSS | 
        
          
              | Base:           | 4.0 |  
              | Impact:         | 4.9 |  
              | Exploitability: | 4.9 |  
           
         | 
      
    
        | Pristup | 
        
        
            | Vektor | Složenost | Autentikacija |  
            
            | NETWORK | 
            HIGH | 
            NONE | 
             
         
         | 
    
      
        | Impact | 
        
        
            | Povjerljivost | Cjelovitost | Dostupnost |  
            
            | PARTIAL | 
            PARTIAL | 
            NONE | 
             
         
         | 
    
    
        | CVSS vektor | 
        AV:N/AC:H/Au:N/C:P/I:P/A:N | 
      
      
          | Zadnje važnije ažuriranje | 
          
            07-04-2016 - 20:55 | 
          
      
      
          | Objavljeno | 
          
            23-12-2013 - 22:55 |