CVE-2013-6422: Canonical Ubuntu Linux
Medium severity, CVSS 4.0. EPSS: 2.8% chance of exploitation in the next 30 days.
The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 12.10 only; version 13.04 only; version 13.10 only
- Debian Debian Linux: version 7.0 only
- Haxx Libcurl: version 7.21.4 only; version 7.21.5 only; version 7.21.6 only; version 7.21.7 only; version 7.22.0 only; version 7.23.0 only; …
Published 2013-12-23. Last modified 2026-06-17.