CVE-2009-2417: High severity libcurl vulnerability
lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2417?
CVE-2009-2417 has a moderate severity level due to its potential for man-in-the-middle attacks.
How do I fix CVE-2009-2417?
To fix CVE-2009-2417, upgrade to a libcurl version higher than 7.19.5, as the vulnerability has been addressed in subsequent releases.
Which versions are affected by CVE-2009-2417?
CVE-2009-2417 affects cURL and libcurl versions from 7.4 through 7.19.5.
What type of attack does CVE-2009-2417 allow?
CVE-2009-2417 allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate.
Is there a patch available for CVE-2009-2417?
Yes, patches are available for affected versions of cURL and libcurl to mitigate CVE-2009-2417.