Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS backend, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Haxx CURL和Libcurl 输入验证漏洞
Vulnerability Description
Haxx Haxx curl和libcurl都是瑞典Haxx公司的产品。curl是一套利用URL语法在命令行下工作的文件传输工具。libcurl是一个免费、开源的客户端URL传输库。 Haxx CURL和Libcurl 7.27.0至7.35.0版本中存在安全漏洞,该漏洞源于当运行在Windows平台并使用SChannel/Winssl TLS后台程序时,程序没有正确验证X.509证书。攻击者可借助任意有效的证书利用该漏洞实施中间人攻击欺骗服务器。
CVSS Information
N/A
Vulnerability Type
N/A