|
|
| |
|
| |
ruby: SSL server spoofing
| Package(s): | ruby |
CVE #(s): | CVE-2013-4073
|
| Created: | June 28, 2013 |
Updated: | August 6, 2013 |
| Description: |
From the Ruby advisory:
When a CA a SSL client trusts allows to issue the server certificate that has null byte in subjectAltName, remote attackers can obtain the certificate for ‘www.ruby-lang.org\0.example.com’ from the CA to spoof ‘www.ruby-lang.org’ and do man-in-the-middle between Ruby’s SSL client and SSL servers. |
| Alerts: |
|
( Log in to post comments)
|
|
|