Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-0139
Description:cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Test IDs: 1.3.6.1.4.1.25623.1.1.10.2015.0165   1.3.6.1.4.1.25623.1.1.4.2014.0691.1   1.3.6.1.4.1.25623.1.0.702902   1.3.6.1.4.1.25623.1.1.4.2015.0962.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-0139
Debian Security Information: DSA-2902 (Google Search)
http://www.debian.org/security/2014/dsa-2902
http://www.mandriva.com/security/advisories?name=MDVSA-2015:213
http://secunia.com/advisories/57836
http://secunia.com/advisories/57966
http://secunia.com/advisories/57968
http://secunia.com/advisories/58615
http://secunia.com/advisories/59458
SuSE Security Announcement: openSUSE-SU-2014:0530 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-04/msg00042.html
http://www.ubuntu.com/usn/USN-2167-1




© 1998-2025 E-Soft Inc. All rights reserved.