Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Gentoo: GLSA 200909-20 Normal: cURL Certificate Handling Issue

gentoo
Calendar Grey September 25, 2009
Dist Gentoo Esm H88
Gentoo Linux Advisory GLSA 202208-15 discusses issues in OpenSSL certificate verification, potentially leading to interception vulnerabilities.
An error in the X.509 certificate handling of cURL might enable remote attackers to conduct man-in-the-middle attacks.

Summary

Gentoo Linux Security Advisory GLSA 200909-20 https://security.gentoo.org/ Severity: Normal Title: cURL: Certificate validation error Date: September 25, 2009 Bugs: #281515 ID: 200909-20

Synopsis ======= An error in the X.509 certificate handling of cURL might enable remote attackers to conduct man-in-the-middle attacks.
Background ========= cURL is a command line tool for transferring files with URL syntax, supporting numerous protocols.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/curl < 7.19.6 >= 7.19.6
========== Scott Cantor reported that cURL does not properly handle fields in X.509 certificates that contain an ASCII NUL (\0) characte...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3730794_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here