CVE-2024-2379
Publication date 27 March 2024
Last updated 24 July 2024
Ubuntu priority
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.
Read the notes from the security team
Why is this CVE low priority?
Upstream developers consider this a low severity issue
Status
Package | Ubuntu Release | Status |
---|---|---|
curl | 24.04 LTS noble |
Not affected
|
22.04 LTS jammy |
Not affected
|
|
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|