Oval Definition:oval:org.mitre.oval:def:20136
Revision Date:2014-06-23Version:6
Title:DSA-2824-1 curl - unchecked tls/ssl certificate host name
Description:Marc Deslauriers discovered that curl, a file retrieval tool, would mistakenly skip verifying the CN and SAN name fields when digital signature verification was disabled in the libcurl GnuTLS backend.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2013-6422
DSA-2824-1
Platform(s):Debian GNU/kFreeBSD 7
Debian GNU/Linux 7
Product(s):curl
Definition Synopsis
  • Debian 7 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND curl DPKG is earlier than 0:7.26.0-1+wheezy7
  • BACK