TROYANOSYVIRUS
Voltar para CVEs

CVE-2025-14017

MEDIUM
6.3

Descricao

When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.

Detalhes CVE

Pontuacao CVSS v3.16.3
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Vetor de ataqueLOCAL
ComplexidadeHIGH
Privilegios necessariosNONE
Interacao do usuarioREQUIRED
Publicado1/8/2026
Ultima modificacao1/27/2026
Fontenvd
Avistamentos honeypot0

Produtos afetados

haxx:curl

Referencias

https://curl.se/docs/CVE-2025-14017.html(2499f714-1537-4658-8207-48ae4bb9eae9)
https://curl.se/docs/CVE-2025-14017.json(2499f714-1537-4658-8207-48ae4bb9eae9)
http://www.openwall.com/lists/oss-security/2026/01/07/3(af854a3a-2127-422b-91ae-364da2661108)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.