6.8

CVE-2013-4073

The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.9.3-p448, and 2.0 before 2.0.0-p247 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Data is provided by the National Vulnerability Database (NVD)
Ruby-langRuby Version1.8.6-26
Ruby-langRuby Version1.8.7
Ruby-langRuby Version1.8.7 Updatep160
Ruby-langRuby Version1.8.7 Updatep17
Ruby-langRuby Version1.8.7 Updatep173
Ruby-langRuby Version1.8.7 Updatep174
Ruby-langRuby Version1.8.7 Updatep22
Ruby-langRuby Version1.8.7 Updatep248
Ruby-langRuby Version1.8.7 Updatep249
Ruby-langRuby Version1.8.7 Updatep299
Ruby-langRuby Version1.8.7 Updatep301
Ruby-langRuby Version1.8.7 Updatep302
Ruby-langRuby Version1.8.7 Updatep330
Ruby-langRuby Version1.8.7 Updatep334
Ruby-langRuby Version1.8.7 Updatep352
Ruby-langRuby Version1.8.7 Updatep357
Ruby-langRuby Version1.8.7 Updatep358
Ruby-langRuby Version1.8.7 Updatep370
Ruby-langRuby Version1.8.7 Updatep371
Ruby-langRuby Version1.8.7 Updatep373
Ruby-langRuby Version1.8.7 Updatep71
Ruby-langRuby Version1.8.7 Updatep72
Ruby-langRuby Version1.8.7 Updatepreview1
Ruby-langRuby Version1.8.7 Updatepreview2
Ruby-langRuby Version1.8.7 Updatepreview3
Ruby-langRuby Version1.8.7 Updatepreview4
Ruby-langRuby Version1.9.3
Ruby-langRuby Version1.9.3 Updatep0
Ruby-langRuby Version1.9.3 Updatep125
Ruby-langRuby Version1.9.3 Updatep194
Ruby-langRuby Version1.9.3 Updatep286
Ruby-langRuby Version1.9.3 Updatep383
Ruby-langRuby Version1.9.3 Updatep385
Ruby-langRuby Version1.9.3 Updatep392
Ruby-langRuby Version1.9.3 Updatep426
Ruby-langRuby Version1.9.3 Updatep429
Ruby-langRuby Version2.0.0 Updatep0
Ruby-langRuby Version2.0.0 Updatep195
Ruby-langRuby Version2.0.0 Updatepreview1
Ruby-langRuby Version2.0.0 Updatepreview2
Ruby-langRuby Version2.0.0 Updaterc1
Ruby-langRuby Version2.0.0 Updaterc2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.66% 0.853
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P