LWN.net Logo

ruby: switch to https for gem installation

Package(s):ruby CVE #(s):
Created:September 5, 2013 Updated:September 5, 2013
Description:

From the openSUSE advisory:

The ruby gemrc configured the gem installation source as http source, allowing man in the middle attacks (if someone could provide a different address for rubygems.org).

Alerts:
openSUSE openSUSE-SU-2013:1393-1 2013-08-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds