cURL / libcURL NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
11 Jul. 2010
Summary
cURL and libcURL are prone to a security-bypass vulnerability because they fail to properly validate the domain name in a signed CA certificate, allowing attackers to substitute malicious SSL certificates for trusted ones.
Vulnerable Systems:
*cURL / libcURL NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
This issue affects cURL and libcURL when compiled against OpenSSL.
Successful exploits allow attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
cURL and libcURL 7.4 through 7.19.5 are vulnerable. Additional applications that use the affected library may also be vulnerable.
Vendor Status:
Vendor as issued an updated vulnerability.