ubuntu · CVE-2007-5770

Quick triage

Priority: low Published: 2007-11-14 01:46:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2007-5770 low priority: Ubuntu including 2 source packages (libopenssl-ruby, ruby1.8), 12 status rows across 6 suites (dapper, edgy, feisty, gutsy, hardy, upstream): not-affected 6, released 6.

Description:

The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the commonName (CN) field in a server certificate matches the domain name in a request sent over SSL, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site, different components than CVE-2007-5162.

cvelogic Threat Intelligence