cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
CVSS Details
- CVSS 3.1 Base Score: 4.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Aug 30, 2017 | Apr 15, 2014 |
| Debian | — | Upgrade curl | Jul 30, 2024 | Apr 15, 2014 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 25, 2014 |
| Gentoo Linux | — | Upgrade net-misc/curl. | Oct 30, 2017 | Apr 15, 2014 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Apr 15, 2014 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libcurlUpgrade curlUpgrade libcurl-devel | Jun 17, 2020 | Apr 15, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 26, 2014 |
| Suse | — | Upgrade libldap-openssl1-2_4-2Upgrade cyrus-sasl-openssl1-gssapiUpgrade cyrus-sasl-openssl1-digestmd5Upgrade libldap-2_4-2-32bitUpgrade cyrus-sasl-openssl1-plainUpgrade openldap2-clientUpgrade openldap2-develUpgrade curlUpgrade openldap2-back-metaUpgrade compat-libldap-2_3-0Upgrade libcurl-develUpgrade libcurl4-32bitUpgrade cyrus-sasl-openssl1-crammd5Upgrade lftpUpgrade cyrus-sasl-openssl1Upgrade libldap-2_4-2Upgrade cyrus-sasl-openssl1-32bitUpgrade libcurl4-openssl1-x86Upgrade libcurl4-openssl1-32bitUpgrade openldap2-back-perlUpgrade curl-openssl1Upgrade libcurl4-x86Upgrade libcurl4Upgrade cyrus-sasl-openssl1-ntlmUpgrade openldap2Upgrade openldap2-devel-32bitUpgrade libldap-2_4-2-x86Upgrade cyrus-sasl-openssl1-otpUpgrade cyrus-sasl-openssl1-x86Upgrade libcurl4-openssl1Upgrade libldap-openssl1-2_4-2-32bitUpgrade libldap-openssl1-2_4-2-x86 | Dec 18, 2015 | Apr 15, 2014 |
| Ubuntu | — | Upgrade libcurl3-nssUpgrade libcurl3Upgrade libcurl3-gnutls | Nov 8, 2024 | Apr 15, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub