[USN-1902-1] Ruby vulnerability
Severity
Medium
CVEs
1
An attacker could trick Ruby into trusting a rogue server.
William (B.J.) Snow Orvis discovered that Ruby incorrectly verified the
hostname in SSL certificates. An attacker could trick Ruby into trusting a
rogue server certificate, which was signed by a trusted certificate
authority, to perform a machine-in-the-middle attack.
- ID
- USN-1902-1
- Severity
- medium
- Severity from
- CVE-2013-4073
- URL
- https://ubuntu.com/security/notices/USN-1902-1
- Published
-
2013-07-09T15:13:12
(11 years ago) - Modified
-
2013-07-09T15:13:12
(11 years ago) - Other Advisories
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |