Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1855

Опубликовано: 30 мар. 2015
Источник: redhat
CVSS2: 4

Описание

verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.

It was discovered that the Ruby OpenSSL extension was overly permissive when verifying host names against X.509 certificate names with wildcards. This could cause Ruby TLS/SSL clients to accept certain certificates as valid, which is a violation of the RFC 6125 recommendations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5.2ruby193-rubyAffected
Red Hat Enterprise Linux 5rubyWill not fix
Red Hat Enterprise Linux 6rubyWill not fix
Red Hat Enterprise Linux 7rubyWill not fix
Red Hat OpenStack Platform 4ruby193-rubyWill not fix
Red Hat Software Collectionsrh-ruby22-rubyNot affected
Red Hat Software Collectionsruby193-rubyWill not fix
Red Hat Software Collectionsruby200-rubyWill not fix
Red Hat Subscription Asset Managerruby193-rubyAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-297
https://bugzilla.redhat.com/show_bug.cgi?id=1209981ruby: OpenSSL extension hostname matching implementation violates RFC 6125

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 6 лет назад

verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.

CVSS3: 5.9
nvd
около 6 лет назад

verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.

CVSS3: 5.9
debian
около 6 лет назад

verify_certificate_identity in the OpenSSL extension in Ruby before 2. ...

github
больше 3 лет назад

verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.

fstec
почти 11 лет назад

Уязвимость интерпретатора Ruby, позволяющая нарушителю подменить SSL-сервер

4 Medium

CVSS2