CVE-2013-6422

Source
https://cve.org/CVERecord?id=CVE-2013-6422
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2013-6422.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2013-6422
Aliases
Downstream
Published
2013-12-23T22:55:02Z
Modified
2026-04-10T03:43:07Z
Summary
[none]
Details

The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

References

Affected packages