5.9

CVE-2015-1855

verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ruby-lang ≫ Ruby Version >= 2.1.0 < 2.1.6
Ruby-lang ≫ Ruby Version >= 2.2.0 < 2.2.2
Ruby-lang ≫ Ruby Version 2.0.0 Update -
Ruby-lang ≫ Ruby Version 2.0.0 Update p0
Ruby-lang ≫ Ruby Version 2.0.0 Update p195
Ruby-lang ≫ Ruby Version 2.0.0 Update p247
Ruby-lang ≫ Ruby Version 2.0.0 Update p353
Ruby-lang ≫ Ruby Version 2.0.0 Update p451
Ruby-lang ≫ Ruby Version 2.0.0 Update p481
Ruby-lang ≫ Ruby Version 2.0.0 Update p576
Ruby-lang ≫ Ruby Version 2.0.0 Update p594
Ruby-lang ≫ Ruby Version 2.0.0 Update p598
Ruby-lang ≫ Ruby Version 2.0.0 Update p643
Ruby-lang ≫ Trunk Version < 50292
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Puppet ≫ Puppet Agent Version 1.0.0
Puppet ≫ Puppet Enterprise Version >= 3.0.0 < 3.8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.82% 0.847
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.debian.org/security/2015/dsa-3245
Third Party Advisory
http://www.debian.org/security/2015/dsa-3246
Third Party Advisory
http://www.debian.org/security/2015/dsa-3247
Third Party Advisory
https://bugs.ruby-lang.org/issues/9644
Third Party Advisory
https://puppetlabs.com/security/cve/cve-2015-1855
Third Party Advisory
https://www.ruby-lang.org/en/news/2015/04/13/ruby-openssl-hostname-matching-vulnerability/
Vendor Advisory