Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST) when the digital signature verification (CURLOPT_SSL_VERIFYPEER) is disabled, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Haxx cURL/libcurl 安全绕过漏洞
Vulnerability Description
Haxx Haxx curl和libcurl都是瑞典Haxx公司的产品。curl是一套利用URL语法在命令行下工作的文件传输工具。libcurl是一个免费、开源的客户端URL传输库。 cURL和libcurl 7.18.0至7.32.0版本中存在安全绕过漏洞,该漏洞源于当禁用数字签名(CURLOPT_SSL_VERIFYPEER)时,cURL工具同时禁用SSL证书主机名检查。攻击者可通过实施中间人攻击利用该漏洞借助特制的证书欺骗SSL服务器。
CVSS Information
N/A
Vulnerability Type
N/A