Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Gentoo: GLSA 200909-20 Normal: cURL Certificate Handling Issue

gentoo
Calendar Grey September 25, 2009
Scroller Gentoo
Gentoo Linux Advisory GLSA 202208-15 discusses issues in OpenSSL certificate verification, potentially leading to interception vulnerabilities.
An error in the X.509 certificate handling of cURL might enable remote attackers to conduct man-in-the-middle attacks.

Summary

Gentoo Linux Security Advisory GLSA 200909-20 https://security.gentoo.org/ Severity: Normal Title: cURL: Certificate validation error Date: September 25, 2009 Bugs: #281515 ID: 200909-20

Synopsis ======= An error in the X.509 certificate handling of cURL might enable remote attackers to conduct man-in-the-middle attacks.
Background ========= cURL is a command line tool for transferring files with URL syntax, supporting numerous protocols.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/curl < 7.19.6 >= 7.19.6
========== Scott Cantor reported that cURL does not properly handle fields in X.509 certificates that contain an ASCII NUL (\0) characte...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround