CVE-2014-8151: Medium severity apple ios and macos vulnerability
The darwinsslconnectstep1 function in lib/vtls/curldarwinssl.c in libcurl 7.31.0 through 7.39.0, when using the DarwinSSL (aka SecureTransport) back-end for TLS, does not check if a cached TLS session validated the certificate when reusing the session, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8151?
CVE-2014-8151 is classified as a high severity vulnerability that could allow man-in-the-middle attacks.
How do I fix CVE-2014-8151?
To fix CVE-2014-8151, update libcurl to a version beyond 7.39.0 or apply patches provided by the software vendor.
What is the impact of CVE-2014-8151?
The impact of CVE-2014-8151 allows attackers to exploit reused TLS sessions without proper certificate validation, potentially intercepting sensitive data.
Which versions of libcurl are affected by CVE-2014-8151?
Affected versions of libcurl include 7.31.0 through 7.39.0.
Is CVE-2014-8151 specific to any operating system?
CVE-2014-8151 affects macOS systems using the DarwinSSL back-end for TLS under specific versions of libcurl.