Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-3739
Description:The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7.49.0, when using SSLv3 or making a TLS connection to a URL that uses a numerical IP address, allow remote attackers to spoof servers via an arbitrary valid certificate.
Test IDs: 1.3.6.1.4.1.25623.1.1.13.2016.141.01  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-3739
BugTraq ID: 90726
http://www.securityfocus.com/bid/90726
https://security.gentoo.org/glsa/201701-47
http://www.openwall.com/lists/oss-security/2024/03/27/4
http://www.securitytracker.com/id/1035907
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.495349




© 1998-2025 E-Soft Inc. All rights reserved.