CVE-2007-5162

Impact:
Moderate
Public Date:
2007-09-27
Bugzilla:
313691: CVE-2007-5162 ruby Net:HTTP insufficient verification of SSL certificate

The MITRE CVE dictionary describes this issue as:

The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS request, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site.

Find out more about CVE-2007-5162 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 4 (ruby) RHSA-2007:0961 2007-11-13
Red Hat Enterprise Linux 5 (ruby) RHSA-2007:0965 2007-11-13

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.