>> Ruby Net::HTTPS Library Common Name Verification Security Weakness
Title : Ruby Net::HTTPS Library Common Name Verification Security Weakness VUPEN ID : VUPEN/ADV-2007-3340 CVE ID : CVE-2007-5162
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-10-03
Technical Description
A weakness has been identified in Ruby, which could be exploited to conduct spoofing attacks. This issue is caused by an error in the Net::HTTPS library that fails to properly validate the common name within SSL certificates against the hostname of the server, which could be exploited by attackers to present a cryptographically valid certificate with an invalid CN and spoof an arbitrary web site.