Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2009-2417

lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

  • Published: Aug 14, 2009
  • Updated: Apr 13, 2023
  • CVE: CVE-2009-2417
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
curl / libcurl 7.17.1 7.17.1.x
libcurl / libcurl 7.13.1 7.13.1.x
curl / libcurl 7.19.4 7.19.4.x
curl / libcurl 7.14 7.14.x
curl / libcurl 7.12.0 7.12.0.x
curl / libcurl 7.14.1 7.14.1.x
curl / libcurl 7.10.5 7.10.5.x
curl / libcurl 7.8.1 7.8.1.x
curl / libcurl 7.10.3 7.10.3.x
curl / libcurl 7.8 7.8.x
curl / libcurl 7.4.2 7.4.2.x
curl / libcurl 7.7.3 7.7.3.x
curl / libcurl 7.9.7 7.9.7.x
curl / libcurl 7.5.2 7.5.2.x
curl / libcurl 7.9.6 7.9.6.x
curl / libcurl 7.10.4 7.10.4.x
curl / libcurl 7.10.2 7.10.2.x
curl / libcurl 7.12.2 7.12.2.x
curl / libcurl 7.7 7.7.x
curl / libcurl 7.17.0 7.17.0.x
curl / libcurl 7.10 7.10.x
curl / libcurl 7.13.1 7.13.1.x
curl / libcurl 7.12.1 7.12.1.x
libcurl / libcurl 7.15.3 7.15.3.x
libcurl / libcurl 7.15.2 7.15.2.x
curl / libcurl 7.11.2 7.11.2.x
libcurl / libcurl 7.14 7.14.x
curl / libcurl 7.10.7 7.10.7.x
curl / libcurl 7.13 7.13.x
libcurl / libcurl 7.14.1 7.14.1.x
curl / libcurl 7.10.8 7.10.8.x
libcurl / libcurl 7.13 7.13.x
curl / libcurl 7.9.1 7.9.1.x
libcurl / libcurl 7.15.1 7.15.1.x
curl / libcurl 7.15.2 7.15.2.x
curl / libcurl 7.5 7.5.x
libcurl / libcurl 7.12.1 7.12.1.x
curl / libcurl 7.15.3 7.15.3.x
curl / libcurl 7.18.0 7.18.0.x
curl / libcurl 7.12.3 7.12.3.x
curl / libcurl 7.19.0 7.19.0.x
curl / libcurl 7.19.1 7.19.1.x
curl / libcurl 7.19.3 7.19.3.x
curl / libcurl 7.10.6 7.10.6.x
curl / libcurl 7.9.5 7.9.5.x
curl / libcurl 7.15.1 7.15.1.x
curl / libcurl 7.7.2 7.7.2.x
libcurl / libcurl 7.15 7.15.x
libcurl / libcurl 7.12.3 7.12.3.x
curl / libcurl 7.12 7.12.x
libcurl / libcurl 7.13.2 7.13.2.x
curl / libcurl 7.18.1 7.18.1.x
curl / libcurl 7.7.1 7.7.1.x
curl / libcurl 7.18.2 7.18.2.x
curl / libcurl 7.9.2 7.9.2.x
curl / libcurl 7.11.1 7.11.1.x
curl / libcurl 7.9 7.9.x
curl / libcurl 7.9.3 7.9.3.x
curl / libcurl 7.4 7.4.x
libcurl / libcurl 7.16.3 7.16.3.x
curl / libcurl 7.19.2 7.19.2.x
curl / libcurl 7.16.3 7.16.3.x
curl / libcurl 7.13.2 7.13.2.x
curl / libcurl 7.15 7.15.x
curl / libcurl 7.6 7.6.x
curl / libcurl 7.5.1 7.5.1.x
curl / libcurl 7.11.0 7.11.0.x
libcurl / libcurl 7.12 7.12.x
curl / libcurl 7.19.5 7.19.5.x
curl / libcurl 7.6.1 7.6.1.x
curl / libcurl 7.10.1 7.10.1.x
curl / libcurl 7.9.8 7.9.8.x
curl / libcurl 7.4.1 7.4.1.x
libcurl / libcurl 7.12.2 7.12.2.x