Bugzilla – Bug 856069
VUL-0: CVE-2013-6422: curl: SSL certificate check disabled when using GNUTLS
Last modified: 2014-01-14 08:49:34 UTC
CVE-2013-6422 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6422 https://bugzilla.redhat.com/show_bug.cgi?id=1037918
bugbot adjusting priority
I think we build curl everywhere with openssl as TLS provider, and not GNUTLS.
(In reply to comment #2) > I think we build curl everywhere with openssl as TLS provider, and not GNUTLS. You're right.
Nothing to fix. Reassigning to security-team.
closing