PT-2017-17755 · Curl+2 · Libcurl+3

Lijian996

·

Publicado

2017-04-19

·

Atualizado

2026-05-18

·

CVE-2017-7468

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions curl and libcurl versions 7.52.0 through 7.53.1
Description The issue arises from libcurl attempting to resume a TLS session even when the client certificate has changed. This is problematic because a server may skip the client certificate check on resume and use the old identity established by the previous certificate. libcurl uses TLS session id/ticket by default to resume previous TLS sessions, which can lead to this flaw. This is a regression issue similar to one previously reported.
Recommendations For versions 7.52.0 through 7.53.1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider disabling the use of TLS session id/ticket to prevent the resumption of TLS sessions with changed client certificates.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1492
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2017-7468
OPENSUSE-SU-2024:10582-1

Produtos afetados

Alt Linux
Ubuntu
Curl
Libcurl