CVE-2024-2466: TLS certificate check bypass with mbedTLS
Accounts. The issue was addressed with improved checks.
Other sources
AirDrop. This issue was addressed through improved state management.
— Apple
apache. This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
— Apple
APFS. The issue was addressed with improved restriction of data container access.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue was addressed with additional code-signing restrictions.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-40804
- CVE-2023-38709
- CVE-2024-24795
- CVE-2024-27316
- CVE-2024-40783
- CVE-2024-40774
- CVE-2024-40814
- CVE-2024-40775
- CVE-2024-27877
- CVE-2024-27878
- CVE-2024-40799
- CVE-2024-27873
- CVE-2024-2004
- CVE-2024-2379
- CVE-2024-2398
- CVE-2024-2466
- CVE-2024-40827
- CVE-2024-40815
- CVE-2024-40795
- CVE-2023-6277
- CVE-2023-52356
- CVE-2024-40806
- CVE-2024-40777
- CVE-2024-40784
- CVE-2024-27863
- CVE-2024-40816
- CVE-2024-40788
- CVE-2024-40803
- CVE-2024-40805
- CVE-2024-40832
- CVE-2024-40796
- CVE-2024-6387
- CVE-2024-40781
- CVE-2024-40802
- CVE-2024-40823
- CVE-2024-27882
- CVE-2024-27883
- CVE-2024-40778
- CVE-2024-40800
- CVE-2023-27952
- CVE-2024-40817
- CVE-2024-40824
- CVE-2024-27871
- CVE-2024-27881
- CVE-2024-40821
- CVE-2024-40798
- CVE-2024-27872
- CVE-2024-27862
- CVE-2024-40833
- CVE-2024-40835
- CVE-2024-40836
- CVE-2024-40807
- CVE-2024-40834
- CVE-2024-40809
- CVE-2024-40812
- CVE-2024-40787
- CVE-2024-40793
- CVE-2024-40818
- CVE-2024-40822
- CVE-2024-40828
- CVE-2024-40811
- CVE-2024-40776
- CVE-2024-40782
- CVE-2024-40779
- CVE-2024-40780
- CVE-2024-40785
- CVE-2024-40789
- CVE-2024-4558
- CVE-2024-40794
- CVE-2024-27826
- CVE-2024-23296
- CVE-2024-44205
- CVE-2024-23261
- CVE-2024-40786
- CVE-2024-40829
- CVE-2024-54564
- CVE-2024-44306
- CVE-2024-44307
- CVE-2024-44141
- CVE-2024-44199
- CVE-2024-40810
- CVE-2024-44305
- CVE-2024-54551
- CVE-2024-44185
- CVE-2024-44206
Frequently Asked Questions
What is the severity of CVE-2024-2466?
CVE-2024-2466 is classified as a high severity vulnerability due to its impact on the security of TLS connections.
How does CVE-2024-2466 affect libcurl users?
CVE-2024-2466 affects libcurl users by allowing potential man-in-the-middle attacks due to improper server certificate validation.
How do I fix CVE-2024-2466?
To fix CVE-2024-2466, you should upgrade libcurl to version 8.7.0 or above if you are using Red Hat or update macOS Monterey to 12.7.6 or later.
What versions of macOS are affected by CVE-2024-2466?
CVE-2024-2466 affects macOS Monterey versions before 12.7.6, macOS Ventura before 13.6.8, and macOS Sonoma before 14.6.
Is there a workaround for CVE-2024-2466?
Currently, there is no explicitly stated workaround for CVE-2024-2466; users are advised to update their software to mitigate the risk.