Package: ruby1.8 Version: 1.8.5-4 Severity: important Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for ruby1.8.
CVE-2007-5162[0]: | The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) | Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the | commonName (CN) field in a server certificate matches the domain name | in an HTTPS request, which makes it easier for remote attackers to | intercept SSL transmissions via a man-in-the-middle attack or spoofed | web site. If you fix this vulnerability please also include the CVE id in your changelog entry. You can find a patch on: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&revision=13504 For further information: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5162 Kind regards Nico -- Nico Golde - http://ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted.
pgp46UWStc19m.pgp
Description: PGP signature

