Record summary

CVE-2015-1855 has a selected CVSS score of 5.9 (medium); EIP currently links 1 repository PoC.

Description

verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE Listbefore 2.0.0 patchlevel 645affected
2.1.x before 2.1.6affected
and 2.2.x before 2.2.2affected

Proofs of concept

1

Repository PoCs

GitHubvpereira/CVE-2015-1855Repository PoCby vpereiraStars: 0Not analyzed4 files

1.1 KiB

GitHub

PoC details

References

7