CVE Vulnerabilities

CVE-2007-3564

Published: Jul 18, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

libcurl 7.14.0 through 7.16.3, when built with GnuTLS support, does not check SSL/TLS certificate expiration or activation dates, which allows remote attackers to bypass certain access restrictions.

Affected Software

Name Vendor Start Version End Version
Libcurl Libcurl 7.14 (including) 7.14 (including)
Libcurl Libcurl 7.14.1 (including) 7.14.1 (including)
Libcurl Libcurl 7.15 (including) 7.15 (including)
Libcurl Libcurl 7.15.1 (including) 7.15.1 (including)
Libcurl Libcurl 7.15.2 (including) 7.15.2 (including)
Libcurl Libcurl 7.15.3 (including) 7.15.3 (including)
Libcurl Libcurl 7.16.3 (including) 7.16.3 (including)
Curl Ubuntu dapper *
Curl Ubuntu devel *
Curl Ubuntu edgy *
Curl Ubuntu feisty *

References