Revision Date: | 2022-05-20 | Version: | 1 |
Title: | CVE-2014-8151 |
Description: |
The darwinssl_connect_step1 function in lib/vtls/curl_darwinssl.c in libcurl 7.31.0 through 7.39.0, when using the DarwinSSL (aka SecureTransport) back-end for TLS, does not check if a cached TLS session validated the certificate when reusing the session, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
|
Family: | unix | Class: | vulnerability |
Status: | | Reference(s): | Mitre CVE-2014-8151 SUSE CVE-2014-8151
|
Platform(s): | SUSE Linux Enterprise Desktop 11 SP2 SUSE Linux Enterprise Desktop 11 SP3 SUSE Linux Enterprise Desktop 12 SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP3 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server for SAP Applications 11 SP2 SUSE Linux Enterprise Server for SAP Applications 11 SP3 SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Software Development Kit 11 SP2 SUSE Linux Enterprise Software Development Kit 11 SP3 SUSE Linux Enterprise Software Development Kit 12
| Product(s): | |
Definition Synopsis |
Release Information SUSE Linux Enterprise Desktop 11 SP2 is installed
OR SUSE Linux Enterprise Desktop 11 SP3 is installed
OR SUSE Linux Enterprise Server 11 SP2 is installed
OR SUSE Linux Enterprise Server 11 SP3 is installed
OR SUSE Linux Enterprise Software Development Kit 11 SP2 is installed
OR SUSE Linux Enterprise Software Development Kit 11 SP3 is installed
AND curl is not affected
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise Desktop 12 is installed
OR SUSE Linux Enterprise Server 12 is installed
OR SUSE Linux Enterprise Software Development Kit 12 is installed
AND curl is not affected
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 is installed
AND curl is not affected
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise Server 11 SP2 is installed
OR SUSE Linux Enterprise Server 11 SP3 is installed
AND curl is not affected
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 is installed
AND curl is not affected
|