debian.org
http://www.debian.org/security/2015/dsa-3245 CVE-2015-1855
MEDIUM
Record summary
CVE-2015-1855 has a selected CVSS score of 5.9 (medium); EIP currently links 1 repository PoC.
Description
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | before 2.0.0 patchlevel 645 | affected | |
| 2.1.x before 2.1.6 | affected | ||
| and 2.2.x before 2.2.2 | affected |
Proofs of concept
1Repository PoCs
GitHubvpereira/CVE-2015-1855Repository PoCby vpereiraStars: 0Not analyzed4 files
References
7debian.org
http://www.debian.org/security/2015/dsa-3246 debian.org
http://www.debian.org/security/2015/dsa-3247 bugs.ruby-lang.org
https://bugs.ruby-lang.org/issues/9644 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-1855 puppetlabs.com
https://puppetlabs.com/security/cve/cve-2015-1855 ruby-lang.org
https://www.ruby-lang.org/en/news/2015/04/13/ruby-openssl-hostname-matching-vulnerability