Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-4947

Published: May 29, 2025Last modified: May 29, 2025

Description

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

Severity score breakdown

ParameterValue
Base score6.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Notes

package curl in Alpaquita repositories built without wolfSSL support

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTScurlNot affected (8.9.0-r0)
StreamcurlNot affected (8.8.0-r0)

References

ON THIS PAGE