7.5
CVSSv2

CVE-2007-3564

Published: 18/07/2007 Updated: 29/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

libcurl 7.14.0 up to and including 7.16.3, when built with GnuTLS support, does not check SSL/TLS certificate expiration or activation dates, which allows remote malicious users to bypass certain access restrictions.

Vulnerable Product Search on Vulmon Subscribe to Product

libcurl libcurl 7.15.2

libcurl libcurl 7.15.3

libcurl libcurl 7.15

libcurl libcurl 7.15.1

libcurl libcurl 7.16.3

libcurl libcurl 7.14

libcurl libcurl 7.14.1

Vendor Advisories

It was discovered that the GnuTLS certificate verification methods implemented in Curl did not check for expiration and activation dates When performing validations, tools using libcurl3-gnutls would incorrectly allow connections to sites using expired certificates ...
It has been discovered that the GnuTLS certificate verification methods implemented in libcurl-gnutls, a solid, usable, and portable multi-protocol file transfer library, did not check for expired or invalid dates For the stable distribution (etch), this problem has been fixed in version 7155-1etch1 We recommend that you upgrade your libcurl3-g ...