Debian: 2798-1: curl: unchecked ssl certificate h
on November 19, 2013
at 7:17 am
Posted In: Uncategorized
(Nov 17) Scott Cantor discovered that curl, a file retrieval tool, would disable the CURLOPT_SSLVERIFYHOST check when the CURLOPT_SSL_VERIFYPEER setting was disabled. This would also disable ssl certificate host name checks when it should have only disabled verification of the certificate trust [More…]