Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the commonName (CN) field in a server certificate matches the domain name in a request sent over SSL, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site, different components than CVE-2007-5162.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ruby Libraries SSL 验证错误漏洞
Vulnerability Description
Ruby 1.8.5 和1.8.6中的(1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop,以及(5) Net::smtp libraries 在无法验证通过SSL发送的域名请求中commonName(Cn)字段在服务器证书匹配,更易于远程攻击者借助一个 中间人攻击或者欺骗性网点拦截SSL传送。
CVSS Information
N/A
Vulnerability Type
N/A