Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-1855
Description:verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.
Test IDs: 1.3.6.1.4.1.25623.1.0.703247   1.3.6.1.4.1.25623.1.1.1.2.2015.235   1.3.6.1.4.1.25623.1.1.10.2015.0178   1.3.6.1.4.1.25623.1.0.120228   1.3.6.1.4.1.25623.1.0.869307   1.3.6.1.4.1.25623.1.0.120053   1.3.6.1.4.1.25623.1.1.1.2.2015.224   1.3.6.1.4.1.25623.1.0.703245   1.3.6.1.4.1.25623.1.0.120227   1.3.6.1.4.1.25623.1.0.120229   1.3.6.1.4.1.25623.1.0.703246   1.3.6.1.4.1.25623.1.0.869647   1.3.6.1.4.1.25623.1.0.120226  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-1855
http://www.debian.org/security/2015/dsa-3245
http://www.debian.org/security/2015/dsa-3246
http://www.debian.org/security/2015/dsa-3247
https://bugs.ruby-lang.org/issues/9644
https://puppetlabs.com/security/cve/cve-2015-1855
https://www.ruby-lang.org/en/news/2015/04/13/ruby-openssl-hostname-matching-vulnerability/




© 1998-2025 E-Soft Inc. All rights reserved.