CVE-2015-1855: Input Validation
Last updated 24 July 2024
Other sources
verifycertificateidentity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1855?
CVE-2015-1855 is a vulnerability classified as high severity due to its potential to allow remote attackers to spoof servers.
How do I fix CVE-2015-1855?
To fix CVE-2015-1855, update your Ruby installation to version 2.0.0 patchlevel 645 or later, or version 2.1.6 or later, or version 2.2.2 or later.
Which versions of Ruby are affected by CVE-2015-1855?
CVE-2015-1855 affects Ruby versions prior to 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2.
What are the implications of CVE-2015-1855 for web applications?
CVE-2015-1855 allows attackers to spoof server identities, potentially leading to man-in-the-middle attacks on web applications.
Is CVE-2015-1855 present in Debian-based systems?
Yes, CVE-2015-1855 is present in the Ruby packages included in Debian systems, specifically in the affected Ruby versions listed.