Ubuntu Security Notice (C) 2008-2013 Canonical, Inc. / NASL script (C) 2008-2013 Tenable Network Security, Inc.
The remote Ubuntu host is missing one or more security-related patches.
Chris Clark discovered that Ruby's HTTPS module did not check for
commonName mismatches early enough during SSL negotiation. If a remote
attacker were able to perform man-in-the-middle attacks, this flaw
could be exploited to view sensitive information in HTTPS requests
coming from Ruby applications. (CVE-2007-5162)
It was discovered that Ruby's FTPTLS, telnets, and IMAPS modules did
not check the commonName when performing SSL certificate checks. If a
remote attacker were able to perform man-in-the-middle attacks, this
flaw could be exploited to eavesdrop on encrypted communications from
Ruby applications using these protocols. (CVE-2007-5770).
Update the affected packages.
Risk factor :
Medium / CVSS Base Score : 5.0
Family: Ubuntu Local Security Checks
Nessus Plugin ID: 31704 ()
CVE ID: CVE-2007-5162CVE-2007-5770
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.