CVE-2013-6422

medium
Published 2013-12-23 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.0

Description

The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2013-6422 NameCVE-2013-6422 DescriptionThe GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec,โ€ฆ

CVE-2013-6422

NameCVE-2013-6422
DescriptionThe GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2824-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
curl (PTS)bullseye7.74.0-1.3+deb11u13fixed
bullseye (security)7.74.0-1.3+deb11u16fixed
bookworm7.88.1-10+deb12u14fixed
bookworm (security)7.88.1-10+deb12u5fixed
trixie8.14.1-2+deb13u3fixed
forky8.20.0-2fixed
sid8.20.0-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
curlsourcesqueeze(not affected)
curlsourcewheezy7.26.0-1+wheezy7DSA-2824-1
curlsource(unstable)7.34.0-1

Notes

[squeeze] - curl <not-affected> (issue introduced with 59cf93cc, 7.21.4)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[squeeze] - curl <not-affected> (issue introduced with 59cf93cc, 7.21.4)

OS impact

ubuntu Ubuntu Affected 4 releases
VersionStatusFixed in
13.10 Affected โ€”
13.04 Affected โ€”
12.10 Affected โ€”
12.04 Affected โ€”
debian Debian Mixed 6 releases
VersionStatusFixed in
trixie Fixed 7.34.0-1
sid Fixed 7.34.0-1
forky Fixed 7.34.0-1
bullseye Fixed 7.34.0-1
bookworm Fixed 7.34.0-1
7.0 Affected โ€”

Application impact

VendorProductVersionsFixed
haxxlibcurl7.21.4
haxxlibcurl7.21.5
haxxlibcurl7.21.6
haxxlibcurl7.21.7
haxxlibcurl7.22.0
haxxlibcurl7.23.0
haxxlibcurl7.23.1
haxxlibcurl7.24.0
haxxlibcurl7.25.0
haxxlibcurl7.26.0
haxxlibcurl7.27.0
haxxlibcurl7.28.0
haxxlibcurl7.28.1
haxxlibcurl7.29.0
haxxlibcurl7.30.0
haxxlibcurl7.31.0
haxxlibcurl7.32.0
haxxlibcurl7.33.0

References

CWEs

CWE-20

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.