• 公告ID (KylinSec-SA-2024-1599)

摘要:

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

安全等级: Low

公告ID: KylinSec-SA-2024-1599

发布日期: 2024年5月27日

关联CVE: CVE-2024-2466  

  • 详细介绍

1. 漏洞描述

   

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2024-2466 KY3.4-4A curl Unaffected
CVE-2024-2466 KY3.4-5 curl Unaffected
CVE-2024-2466 KY3.5.1 curl Unaffected
CVE-2024-2466 KY3.5.2 curl Unaffected
CVE-2024-2466 V6 curl Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2024-1598 下一篇:KylinSec-SA-2024-1600