← Back

CVE-2015-1855

nvd nist
Published: Nov 29, 2019Modified: Nov 21, 2024

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.

Affected (19)

2 products
Ruby
Trunk
1 product
Debian Linux
2 products
Puppet Agent
Puppet Enterprise
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Ruby Lang
From 2.1.0 to 2.1.6
From 2.2.0 to 2.2.2
Version 2.0.0
Version 2.0.0 p0
Version 2.0.0 p195
Version 2.0.0 p247
Version 2.0.0 p353
Version 2.0.0 p451
Version 2.0.0 p481
Version 2.0.0 p576
Version 2.0.0 p594
Version 2.0.0 p598
Version 2.0.0 p643
Before 50292
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 7.0
Version 8.0
Version 9.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.0.0
From 3.0.0 to 3.8.0

References (12)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.