Mandriva Linux Security Advisory – Ruby network libraries Net::HTTP, Net::IMAP, Net::FTPTLS, Net::Telnet, Net::POP3, and Net::SMTP, up to Ruby version 1.8.6 are affected by a possible man-in-the-middle attack, when using SSL, due to a missing check of the CN (common name) attribute in SSL certificates against the server’s hostname.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/63183/MDVSA-2008-029.txt
Source: https://packetstormsecurity.com/files/63183/Mandriva-Linux-Security-Advisory-2008-029.html

