CURL-CVE-2011-3389

    Dashboard / Vulnerabilities / CURL-CVE-2011-3389

    CURL-CVE-2011-3389

    Published: 24 Jan 2012Last Modified: 1 Jun 2026

    Summary: SSL CBC IV vulnerability

    Details: curl is vulnerable to a SSL CBC IV vulnerability when built to use OpenSSL for the SSL/TLS layer. This vulnerability has been identified (CVE-2011-3389 aka the "BEAST" attack) and is addressed by OpenSSL already as they have made a workaround to mitigate the problem. When doing so, they figured out that some servers did not work with the workaround and offered a way to disable it. The bit used to disable the workaround was then added to the generic `SSL_OP_ALL` bitmask that SSL clients may use to enable workarounds for better compatibility with servers. libcurl uses the SSL_OP_ALL bitmask. While `SSL_OP_ALL` is documented to enable "rather harmless" workarounds, it does in this case effectively enable this security vulnerability again.

    References:

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 7.10.6
    Fixed -7.24.0

    Affected versions

    7.23.1
    7.23.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High