CVE-2007-5770Improper Authentication in Ruby

Severity
5.0MEDIUMNVD
CNA4.3
EPSS
7.7%
top 8.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 14
Latest updateMay 1

Description

The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the commonName (CN) field in a server certificate matches the domain name in a request sent over SSL, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site, different components than CVE-2007-5162.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDruby-lang/ruby1.8.5, 1.8.6+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mf83-c25g-48r6: The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 12022-05-01
CVEList
CVE-2007-5770: The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 12007-11-14

📋Vendor Advisories

2
Ubuntu
Ruby vulnerabilities2008-03-26
Red Hat
net:: * modules2007-10-08

💬Community

1
Bugzilla
CVE-2007-5770 ruby insufficient verification of SSL certificate in various net::* modules2007-11-01
CVE-2007-5770 — Improper Authentication in Ruby | cvebase