Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-2379

Published: March 28, 2024Last modified: July 29, 2024

Description

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

Severity score breakdown

ParameterValue
Base score6.3
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTScurlNot affected (8.5.0-r1)
StreamcurlFixed (8.7.1-r0)

References

ON THIS PAGE