LWN.net Logo

curl: insufficient verification methods

Package(s):curl CVE #(s):CVE-2007-3564
Created:July 17, 2007 Updated:July 19, 2007
Description: The GnuTLS certificate verification methods implemented in Curl did not check for expiration and activation dates. When performing validations, tools using libcurl3-gnutls would incorrectly allow connections to sites using expired certificates.
Alerts:
Debian DSA-1333 2007-07-18
Ubuntu USN-484-1 2007-07-17

(Log in to post comments)

curl: insufficient verification methods

Posted Jul 19, 2007 9:26 UTC (Thu) by cortana (subscriber, #24596) [Link]

This is DSA-1333.

curl: insufficient verification methods

Posted Jul 19, 2007 20:53 UTC (Thu) by smithj (subscriber, #38034) [Link]

Neither rPath Linux nor Foresight Linux are affected by this vulnerability as we do not build curl with GnuTLS support.

Reference:
https://issues.rpath.com/browse/RPL-1532

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds