摘要:
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.
安全等级: Low
公告ID: KylinSec-SA-2024-1598
发布日期: 2024年5月27日
关联CVE: CVE-2024-2379
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2024-2379 | KY3.4-4A | curl | Unaffected |
CVE-2024-2379 | KY3.4-5 | curl | Unaffected |
CVE-2024-2379 | KY3.5.1 | curl | Unaffected |
CVE-2024-2379 | KY3.5.2 | curl | Unaffected |
CVE-2024-2379 | V6 | curl | Unaffected |