VDB

GCVE-110-MAGEIA-2013-338

GCVE-110-MAGEIA-2013-338
Advisory Published
Vulnetix · Advisory published November 20, 2013
Updated curl packages fix security vulnerability: Scott Cantor discovered that curl, a file retrieval tool, would disable the CURLOPT_SSLVERIFYHOST check when the CURLOPT_SSL_VERIFYPEER setting was disabled. This would also disable ssl certificate host name checks when it should have only disabled verification of the certificate trust chain (CVE-2013-4545).

Affected Products

VendorProductVersionsPlatforms
Mageiacurl0 (affected), 7.24.0-1.3.mga2 (unaffected)
Mageiacurl0 (affected), 7.28.1-6.2.mga3 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›