CVE-2017-2629
Summary
| CVE | CVE-2017-2629 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-27 19:29:00 UTC |
| Updated | 2019-10-09 23:26:00 UTC |
| Description | curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for a test success or failure. It ends up always thinking there's valid proof, even when there is none or if the server doesn't support the TLS extension in question. This could lead to users not detecting when a server's certificate goes invalid or otherwise be mislead that the server is in a better shape than it is in reality. This flaw also exists in the command line tool (--cert-status). |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1425746 – (CVE-2017-2629) CVE-2017-2629 curl: SSL_VERIFYSTATUS ignored | CONFIRM | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| cURL: Certificate validation error (GLSA 201703-04) — Gentoo security | GENTOO | security.gentoo.org | Third Party Advisory |
| cURL OCSP Stapling Verification Bug Lets Remote Users Bypass CURLOPT_SSL_VERIFYSTATUS Security Restrictions on the Target System - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| cURL/libcURL CVE-2017-2629 TLS Certificate Validation Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| curl - SSL_VERIFYSTATUS ignored | CONFIRM | curl.haxx.se | Vendor Advisory |
| [R1] LCE 5.0.1 Fixes Two Third-party Library Vulnerabilities - Security Advisory | Tenable™ | CONFIRM | www.tenable.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.