CVE-2014-0139: Medium severity haxx curl vulnerability
cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0139?
CVE-2014-0139 has a medium severity rating, allowing potential man-in-the-middle attacks.
How do I fix CVE-2014-0139?
To fix CVE-2014-0139, upgrade your cURL or libcurl version to at least 7.36.0.
Which versions are affected by CVE-2014-0139?
CVE-2014-0139 affects cURL versions prior to 7.36.0, including versions like 7.10.6 to 7.35.0.
What type of vulnerability is CVE-2014-0139?
CVE-2014-0139 is a vulnerability that allows spoofing via a crafted SSL certificate.
What libraries does CVE-2014-0139 affect?
CVE-2014-0139 affects cURL and libcurl when using OpenSSL, axtls, qsossl, or gskit libraries.