{"id":"DEBIAN-CVE-2024-2379","details":"libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.","modified":"2026-09-15T09:02:55.102085498Z","published":"2024-03-27T08:15:41.230Z","upstream":["CVE-2024-2379"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-2379"}],"affected":[{"package":{"name":"curl","ecosystem":"Debian:12","purl":"pkg:deb/debian/curl?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.88.1-10","7.88.1-10+deb12u1","7.88.1-10+deb12u11","7.88.1-10+deb12u12","7.88.1-10+deb12u13","7.88.1-10+deb12u14","7.88.1-10+deb12u15","7.88.1-10+deb12u1~bpo11+1","7.88.1-10+deb12u2","7.88.1-10+deb12u3","7.88.1-10+deb12u3~bpo11+1","7.88.1-10+deb12u4","7.88.1-10+deb12u5","7.88.1-10+deb12u5~bpo11+1","7.88.1-10+deb12u6","7.88.1-10+deb12u6~bpo11+1","7.88.1-10+deb12u7","7.88.1-10+deb12u8","7.88.1-10+deb12u9","7.88.1-11","8.0.1-1~exp1","8.10.0-1","8.10.0-2","8.10.1-1","8.10.1-1~bpo12+1","8.10.1-2","8.11.0-1","8.11.1-1","8.11.1-1~bpo12+1","8.12.0+git20250209.89ed161+ds-1","8.12.0+git20250209.89ed161+ds-1~bpo12+1","8.12.1-1","8.12.1-2","8.12.1-2~bpo12+1","8.12.1-3","8.12.1-3~bpo12+1","8.13.0-1","8.13.0-1+exp1","8.13.0-2","8.13.0-2+exp1","8.13.0-3","8.13.0-4","8.13.0-4+exp1","8.13.0-5","8.13.0-5+exp1","8.13.0-5~bpo12+1","8.13.0~rc-1~exp1","8.13.0~rc-1~exp2","8.13.0~rc2-1","8.13.0~rc2-2","8.13.0~rc3-1","8.13.0~rc3-1+exp1","8.14.0-1","8.14.0-1+exp1","8.14.0~rc1-1+exp1","8.14.0~rc2-1+exp1","8.14.0~rc3-1+exp1","8.14.1-1","8.14.1-1~bpo12+1","8.14.1-2","8.14.1-2+exp1","8.14.1-2~bpo12+1","8.15.0-1","8.15.0-1~bpo13+1","8.15.0-1~exp1","8.15.0~rc1-1exp1","8.15.0~rc2-1~exp1","8.15.0~rc3-1~exp1","8.16.0-1","8.16.0-1+exp1","8.16.0-1~bpo13+1","8.16.0-2","8.16.0-3","8.16.0-4","8.16.0-4~bpo13+1","8.16.0~rc1-1~exp1","8.16.0~rc2-1","8.16.0~rc2-2","8.16.0~rc3-1","8.17.0-1","8.17.0-2","8.17.0-3","8.17.0~rc1-1~exp1","8.17.0~rc2-1","8.17.0~rc3-1","8.18.0-1","8.18.0-1~bpo13+1","8.18.0-2","8.18.0~rc1-1+exp1","8.18.0~rc2-1","8.18.0~rc3-1","8.19.0-1","8.19.0-1+exp1","8.19.0-1~bpo13+1","8.19.0-2","8.19.0-3","8.19.0-3+exp1","8.19.0-3+exp2","8.19.0~rc1-1~exp1","8.19.0~rc2-1","8.19.0~rc2-2","8.19.0~rc3-1","8.2.1-1","8.2.1-2","8.2.1-2~bpo12+1","8.20.0-1","8.20.0-1+exp","8.20.0-2","8.20.0-2+exp1","8.20.0-2~bpo13+1","8.20.0-3","8.20.0-4","8.20.0-5","8.20.0-5~bpo13+1","8.20.0~rc1-1+exp1","8.20.0~rc1-1+exp2","8.20.0~rc1-1+exp3","8.20.0~rc2-1","8.20.0~rc2-1+exp1","8.20.0~rc3-1","8.20.0~rc3-1+exp1","8.21.0-1","8.21.0-1+exp1","8.21.0-2","8.21.0-2+exp1","8.21.0-2~bpo13+1","8.21.0~rc1-1+exp1","8.21.0~rc2-1","8.21.0~rc2-1+exp1","8.21.0~rc3-1","8.21.0~rc3-1+exp1","8.22.0-1","8.22.0-1+exp1","8.22.0~rc2-1","8.22.0~rc2-2","8.22.0~rc3-1","8.22.0~rc3-1+exp1","8.3.0-1","8.3.0-2","8.3.0-2~bpo12+1","8.3.0-2~exp1","8.3.0-3","8.4.0-1","8.4.0-2","8.4.0-2~bpo12+1","8.5.0-1","8.5.0-1+exp1","8.5.0-2","8.5.0-2+exp1","8.5.0-2~bpo12+1","8.6.0-1","8.6.0-1.1","8.6.0-2","8.6.0-3","8.6.0-3.1","8.6.0-3.1~exp1","8.6.0-3.1~exp2","8.6.0-3.2","8.6.0-4","8.7.1-1","8.7.1-1+exp1","8.7.1-2","8.7.1-3","8.7.1-4","8.7.1-5","8.7.1-5+exp1","8.7.1-5~bpo12+1","8.8.0-1","8.8.0-1+exp1","8.8.0-1+exp2","8.8.0-1~bpo12+1","8.8.0-2","8.8.0-3","8.8.0-4","8.9.0-1","8.9.0-2","8.9.0-3","8.9.1-1","8.9.1-2","8.9.1-2~bpo12+1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-2379.json"}},{"package":{"name":"curl","ecosystem":"Debian:13","purl":"pkg:deb/debian/curl?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.7.1-1"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-2379.json"}},{"package":{"name":"curl","ecosystem":"Debian:14","purl":"pkg:deb/debian/curl?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.7.1-1"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-2379.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"}]}