mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 01:02:25 +00:00
41 lines
1.9 KiB
JSON
41 lines
1.9 KiB
JSON
{
|
|
"id": "CVE-2024-2466",
|
|
"sourceIdentifier": "2499f714-1537-4658-8207-48ae4bb9eae9",
|
|
"published": "2024-03-27T08:15:41.343",
|
|
"lastModified": "2024-05-03T13:15:21.893",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc)."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "libcurl no verific\u00f3 el certificado del servidor de las conexiones TLS realizadas a un host especificado como direcci\u00f3n IP, cuando se cre\u00f3 para usar mbedTLS. libcurl evitar\u00eda err\u00f3neamente el uso de la funci\u00f3n establecer nombre de host cuando el nombre de host especificado se proporcionara como direcci\u00f3n IP, por lo que se saltar\u00eda por completo la verificaci\u00f3n del certificado. Esto afecta a todos los usos de los protocolos TLS (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc)."
|
|
}
|
|
],
|
|
"metrics": {},
|
|
"references": [
|
|
{
|
|
"url": "http://www.openwall.com/lists/oss-security/2024/03/27/4",
|
|
"source": "2499f714-1537-4658-8207-48ae4bb9eae9"
|
|
},
|
|
{
|
|
"url": "https://curl.se/docs/CVE-2024-2466.html",
|
|
"source": "2499f714-1537-4658-8207-48ae4bb9eae9"
|
|
},
|
|
{
|
|
"url": "https://curl.se/docs/CVE-2024-2466.json",
|
|
"source": "2499f714-1537-4658-8207-48ae4bb9eae9"
|
|
},
|
|
{
|
|
"url": "https://hackerone.com/reports/2416725",
|
|
"source": "2499f714-1537-4658-8207-48ae4bb9eae9"
|
|
},
|
|
{
|
|
"url": "https://security.netapp.com/advisory/ntap-20240503-0010/",
|
|
"source": "2499f714-1537-4658-8207-48ae4bb9eae9"
|
|
}
|
|
]
|
|
} |