CVE-2014-8151 describes a vulnerability in libcurl versions 7.31.0 through 7.39.0, specifically when using the DarwinSSL backend for TLS, affecting Apple and Haxx libcurl implementations on macOS. The flaw allows man-in-the-middle attackers to spoof servers by reusing a cached TLS session without proper certificate validation. With a CVSS score of 5.8, this medium-severity vulnerability requires medium attack complexity and can lead to partial confidentiality and integrity compromise. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.10.4CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
7.31.0CPE matchmatch criteria | cpe:2.3:a:haxx:libcurl:7.31.0:*:*:*:*:*:*:* | ||
7.32.0CPE matchmatch criteria | cpe:2.3:a:haxx:libcurl:7.32.0:*:*:*:*:*:*:* | ||
7.33.0CPE matchmatch criteria | cpe:2.3:a:haxx:libcurl:7.33.0:*:*:*:*:*:*:* | ||
7.34.0CPE matchmatch criteria | cpe:2.3:a:haxx:libcurl:7.34.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
curl: certificate check bypass when built with DarwinSSL as TLS backend
Jan 8, 2015Secure Transport certificate check bypass
Jan 8, 2015Secure Transport certificate check bypass
Jan 8, 2015