First published: Tue Nov 13 2007(Updated: )
Ruby is an interpreted scripting language for object-oriented programming.<br>An SSL certificate validation flaw was discovered in several Ruby Net<br>modules. The libraries were not checking the requested host name against<br>the common name (CN) in the SSL server certificate, possibly allowing a man<br>in the middle attack. (CVE-2007-5162, CVE-2007-5770)<br>Users of Ruby should upgrade to these updated packages, which contain a<br>backported patch to resolve these issues.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ruby | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-devel | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-devel | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-docs | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-irb | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-libs | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-libs | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-mode | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-rdoc | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-ri | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-tcltk | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-docs | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-irb | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-mode | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-rdoc | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-ri | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
redhat/ruby-tcltk | <1.8.5-5.el5_1.1 | 1.8.5-5.el5_1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.