Debian Security Advisory 2824-1
http://packetstormsecurity.com/files/124516/dsa-2824-1.txt
Debian Linux Security Advisory 2824-1 - Marc Deslauriers discovered that curl, a file retrieval tool, would mistakenly skip verifying the CN and SAN name fields when digital signature verification was disabled in the libcurl GnuTLS backend.