VYPR
Unrated severityNVD Advisory· Published Jan 15, 2015· Updated May 6, 2026

CVE-2014-8151

CVE-2014-8151

Description

The darwinssl_connect_step1 function in lib/vtls/curl_darwinssl.c in libcurl 7.31.0 through 7.39.0, when using the DarwinSSL (aka SecureTransport) back-end for TLS, does not check if a cached TLS session validated the certificate when reusing the session, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

Affected products

11
  • Haxx/Libcurl10 versions
    cpe:2.3:a:haxx:libcurl:7.31.0:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:haxx:libcurl:7.31.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.32.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.33.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.34.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.35.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.36.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.37.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.37.1:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.38.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.39:*:*:*:*:*:*:*
  • cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
    Range: <=10.10.4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.