NA

CVE-2024-2379

Published: 27/03/2024 Updated: 01/05/2024

Vulnerability Summary

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [SECURITY ADVISORY] curl: CVE-2024-2379: QUIC certificate check bypass with wolfSSL <!--X-Subject-Header-End--> <!--X-Head-of- ...