https://seclists.org/oss-sec/2024/q1/254: [SECURITY ADVISORY] curl: CVE-2024-2379: QUIC certificate check bypass with wolfSSL
Published Mar 27, 2024
·Updated
Affected Software
2 affected components
curl curl
wolfSSL wolfssl
Frequently Asked Questions
1
What is the severity of CVE-2024-2379?
CVE-2024-2379 is classified as a high severity vulnerability due to the potential for security certificate bypass.
2
How do I fix CVE-2024-2379?
To fix CVE-2024-2379, update curl and wolfSSL to the latest versions that contain patches for this vulnerability.
3
What impact does CVE-2024-2379 have on curl and wolfSSL users?
CVE-2024-2379 allows attackers to bypass certificate checks in QUIC connections, which could lead to man-in-the-middle attacks.
4
Which versions of curl are affected by CVE-2024-2379?
CVE-2024-2379 affects specific versions of curl that integrate with wolfSSL prior to the release of security patches.
5
Is CVE-2024-2379 remotely exploitable?
Yes, CVE-2024-2379 can be exploited remotely if the vulnerable versions of curl are used in a networked environment.