Get a Pentest and security assessment of your IT network.

Advisories

Ubuntu Security Notice 596-1

Ubuntu Security Notice 596-1 – Chris Clark discovered that Ruby’s HTTPS module did not check for commonName mismatches early enough during SSL negotiation. If a remote attacker were able to perform man-in-the-middle attacks, this flaw could be exploited to view sensitive information in HTTPS requests coming from Ruby applications. It was discovered that Ruby’s FTPTLS, telnets, and IMAPS modules did not check the commonName when performing SSL certificate checks. If a remote attacker were able to perform man-in-the-middle attacks, this flaw could be exploited to eavesdrop on encrypted communications from Ruby applications using these protocols.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/64912/USN-596-1.txt

Source: https://packetstormsecurity.com/files/64912/Ubuntu-Security-Notice-596-1.html

Related posts
Advisories

crossZone.txt

Advisories

Secunia Security Advisory 16900

Advisories

Secunia Security Advisory 19793

Advisories

Secunia Security Advisory 22534