Title : cURL GnuTLS Certificate Verification Methods Security Bypass Weakness VUPEN ID : VUPEN/ADV-2007-2551 CVE ID : CVE-2007-3564
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-18
Technical Description
A weakness has been identified in cURL, which could be exploited by attackers to bypass security restrictions. This issue is caused by errors within the GnuTLS certificate verification methods that do not properly check for expiration and activation dates, which could cause a vulnerable application to allow connections to sites using expired certificates.