CVE Vulnerabilities

CVE-2009-2417

Published: Aug 14, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a 0 character in a domain name in the subjects Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Affected Software

NameVendorStart VersionEnd Version
LibcurlCurl7.4 (including)7.4 (including)
LibcurlCurl7.4.1 (including)7.4.1 (including)
LibcurlCurl7.4.2 (including)7.4.2 (including)
LibcurlCurl7.5 (including)7.5 (including)
LibcurlCurl7.5.1 (including)7.5.1 (including)
LibcurlCurl7.5.2 (including)7.5.2 (including)
LibcurlCurl7.6 (including)7.6 (including)
LibcurlCurl7.6.1 (including)7.6.1 (including)
LibcurlCurl7.7 (including)7.7 (including)
LibcurlCurl7.7.1 (including)7.7.1 (including)
LibcurlCurl7.7.2 (including)7.7.2 (including)
LibcurlCurl7.7.3 (including)7.7.3 (including)
LibcurlCurl7.8 (including)7.8 (including)
LibcurlCurl7.8.1 (including)7.8.1 (including)
LibcurlCurl7.9 (including)7.9 (including)
LibcurlCurl7.9.1 (including)7.9.1 (including)
LibcurlCurl7.9.2 (including)7.9.2 (including)
LibcurlCurl7.9.3 (including)7.9.3 (including)
LibcurlCurl7.9.5 (including)7.9.5 (including)
LibcurlCurl7.9.6 (including)7.9.6 (including)
LibcurlCurl7.9.7 (including)7.9.7 (including)
LibcurlCurl7.9.8 (including)7.9.8 (including)
LibcurlCurl7.10 (including)7.10 (including)
LibcurlCurl7.10.1 (including)7.10.1 (including)
LibcurlCurl7.10.2 (including)7.10.2 (including)
LibcurlCurl7.10.3 (including)7.10.3 (including)
LibcurlCurl7.10.4 (including)7.10.4 (including)
LibcurlCurl7.10.5 (including)7.10.5 (including)
LibcurlCurl7.10.6 (including)7.10.6 (including)
LibcurlCurl7.10.7 (including)7.10.7 (including)
LibcurlCurl7.10.8 (including)7.10.8 (including)
LibcurlCurl7.11.0 (including)7.11.0 (including)
LibcurlCurl7.11.1 (including)7.11.1 (including)
LibcurlCurl7.11.2 (including)7.11.2 (including)
LibcurlCurl7.12 (including)7.12 (including)
LibcurlCurl7.12.0 (including)7.12.0 (including)
LibcurlCurl7.12.1 (including)7.12.1 (including)
LibcurlCurl7.12.2 (including)7.12.2 (including)
LibcurlCurl7.12.3 (including)7.12.3 (including)
LibcurlCurl7.13 (including)7.13 (including)
LibcurlCurl7.13.1 (including)7.13.1 (including)
LibcurlCurl7.13.2 (including)7.13.2 (including)
LibcurlCurl7.14 (including)7.14 (including)
LibcurlCurl7.14.1 (including)7.14.1 (including)
LibcurlCurl7.15 (including)7.15 (including)
LibcurlCurl7.15.1 (including)7.15.1 (including)
LibcurlCurl7.15.2 (including)7.15.2 (including)
LibcurlCurl7.15.3 (including)7.15.3 (including)
LibcurlCurl7.16.3 (including)7.16.3 (including)
LibcurlCurl7.17.0 (including)7.17.0 (including)
LibcurlCurl7.17.1 (including)7.17.1 (including)
LibcurlCurl7.18.0 (including)7.18.0 (including)
LibcurlCurl7.18.1 (including)7.18.1 (including)
LibcurlCurl7.18.2 (including)7.18.2 (including)
LibcurlCurl7.19.0 (including)7.19.0 (including)
LibcurlCurl7.19.1 (including)7.19.1 (including)
LibcurlCurl7.19.2 (including)7.19.2 (including)
LibcurlCurl7.19.3 (including)7.19.3 (including)
LibcurlCurl7.19.4 (including)7.19.4 (including)
LibcurlCurl7.19.5 (including)7.19.5 (including)
LibcurlLibcurl7.12 (including)7.12 (including)
LibcurlLibcurl7.12.1 (including)7.12.1 (including)
LibcurlLibcurl7.12.2 (including)7.12.2 (including)
LibcurlLibcurl7.12.3 (including)7.12.3 (including)
LibcurlLibcurl7.13 (including)7.13 (including)
LibcurlLibcurl7.13.1 (including)7.13.1 (including)
LibcurlLibcurl7.13.2 (including)7.13.2 (including)
LibcurlLibcurl7.14 (including)7.14 (including)
LibcurlLibcurl7.14.1 (including)7.14.1 (including)
LibcurlLibcurl7.15 (including)7.15 (including)
LibcurlLibcurl7.15.1 (including)7.15.1 (including)
LibcurlLibcurl7.15.2 (including)7.15.2 (including)
LibcurlLibcurl7.15.3 (including)7.15.3 (including)
LibcurlLibcurl7.16.3 (including)7.16.3 (including)
Red Hat Enterprise Linux 3RedHatcurl-0:7.10.6-10.rhel3*
Red Hat Enterprise Linux 4RedHatcurl-0:7.12.1-11.1.el4_8.1*
Red Hat Enterprise Linux 5RedHatcurl-0:7.15.5-2.1.el5_3.5*
CurlUbuntudapper*
CurlUbuntudevel*
CurlUbuntuhardy*
CurlUbuntuintrepid*
CurlUbuntujaunty*
CurlUbuntuupstream*

References