Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An attacker could trick Ruby into trusting a rogue server.
Software Description:
- ruby1.8: Object-oriented scripting language
- ruby1.9.1: Object-oriented scripting language
Details:
William (B.J.) Snow Orvis discovered that Ruby incorrectly verified the
hostname in SSL certificates. An attacker could trick Ruby into trusting a
rogue server certificate, which was signed by a trusted certificate
authority, to perform a man-in-the-middle attack.
The problem can be corrected by updating your system to the following package versions: Ubuntu 13.04: libruby1.8 1.8.7.358-7ubuntu1.1 libruby1.9.1 1.9.3.194-8.1ubuntu1.1 ruby1.8 1.8.7.358-7ubuntu1.1 ruby1.9.1 1.9.3.194-8.1ubuntu1.1 Ubuntu 12.10: libruby1.8 1.8.7.358-4ubuntu0.3 libruby1.9.1 1.9.3.194-1ubuntu1.5 ruby1.8 1.8.7.358-4ubuntu0.3 ruby1.9.1 1.9.3.194-1ubuntu1.5 Ubuntu 12.04 LTS: libruby1.8 1.8.7.352-2ubuntu1.3 libruby1.9.1 1.9.3.0-1ubuntu2.7 ruby1.8 1.8.7.352-2ubuntu1.3 ruby1.9.1 1.9.3.0-1ubuntu2.7 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-1902-1
CVE-2013-4073
Get the latest Linux and open source security news straight to your inbox.