Bug 856069 (CVE-2013-6422) - VUL-0: CVE-2013-6422: curl: SSL certificate check disabled when using GNUTLS
Summary: VUL-0: CVE-2013-6422: curl: SSL certificate check disabled when using GNUTLS
Status: RESOLVED INVALID
Alias: CVE-2013-6422
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-12-18 09:43 UTC by Sebastian Krahmer
Modified: 2014-01-14 08:49 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Swamp Workflow Management 2013-12-18 23:00:24 UTC
bugbot adjusting priority
Comment 2 Marcus Meissner 2013-12-19 09:53:22 UTC
I think we build curl everywhere with openssl as TLS provider, and not GNUTLS.
Comment 3 Vítězslav Čížek 2014-01-02 13:57:39 UTC
(In reply to comment #2)
> I think we build curl everywhere with openssl as TLS provider, and not GNUTLS.

You're right.
Comment 4 Vítězslav Čížek 2014-01-13 15:10:49 UTC
Nothing to fix.
Reassigning to security-team.
Comment 5 Sebastian Krahmer 2014-01-14 08:49:34 UTC
closing