Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] [SECURITY] [DSA 1411-1] New libopenssl-ruby packages fix insecure SSL certificate validation |
|---|---|
| Date: | Sun, 25 Nov 2007 09:09:18 +0100 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-1411-1 security@debian.org http://www.debian.org/security/ Moritz Muehlenhoff November 24, 2007 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : libopenssl-ruby Vulnerability : programming error Problem type : local/remote Debian-specific: no CVE Id(s) : CVE-2007-5162 CVE-2007-5770 Several vulnerabilities have been discovered in Ruby, an object-oriented scripting language. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-5162 It was discovered that the Ruby HTTP(S) module performs insufficient validation of SSL certificates, which may lead to man-in-the-middle attacks. CVE-2007-5770 It was discovered that the Ruby modules for FTP, Telnet, IMAP, POP and SMTP perform insufficient validation of SSL certificates, which may lead to man-in-the-middle attacks. The stable distribution (etch) no longer contains libopenssl-ruby. For the old stable distribution (sarge), these problems have been fixed in version 0.1.4a-1sarge1. Packages for sparc will be provided later. We recommend that you upgrade your libopenssl-ruby packages. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian 3.1 (oldstable) - ---------------------- Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, m68k, mips, mipsel, powerpc, s390 and sparc. Source archives: http://security.debian.org/pool/updates/main/libo/libopenssl-ruby/libopenssl-ruby_0.1.4a-1sarge1.diff.gz Size/MD5 checksum: 4416 25ee3170c96536d66cd8640474bebf85 http://security.debian.org/pool/updates/main/libo/libopenssl-ruby/libopenssl-ruby_0.1.4a.orig.tar.gz Size/MD5 checksum: 84122 303d0473fdb1480a0936a5661d8ba8e3 http://security.debian.org/pool/updates/main/libo/libopenssl-ruby/libopenssl-ruby_0.1.4a-1sarge1.dsc Size/MD5 checksum: 654 b1f510c66bbb4af526741c8d5911ffba alpha architecture (DEC Alpha) http://security.debian.org/pool/updates/main/libo/libopenssl-ruby/libopenssl-ruby1.6_0.1.4a-1sarge1_alpha.deb Size/MD5 checksum: 99566 17d715cd50ba41f6c139844de72b50a0 amd64 architecture (AMD x86_64 (AMD64)) http://security.debian.org/pool/updates/main/libo/libopenssl-ruby/libopenssl-ruby1.6_0.1.4a-1sarge1_amd64.deb Size/MD5 checksum: 97832 3a57407b743683544483941f8739f276 arm architecture (ARM) http://security.debian.org/pool/updates/main/libo/libopenssl-ruby/libopenssl-ruby1.6_0.1.4a-1sarge1_arm.deb Size/MD5 checksum: 90504 80218918d52c9063de2679a0ef308350 hppa architecture (HP PA RISC) http://security.debian.org/pool/updates/main/libo/libopenssl-ruby/libopenssl-ruby1.6_0.1.4a-1sarge1_hppa.deb Size/MD5 checksum: 102480 5b217e95e5acd0b41ef69f0fa373ed73 i386 architecture (Intel ia32) http://security.debian.org/pool/updates/main/libo/libopenssl-ruby/libopenssl-ruby1.6_0.1.4a-1sarge1_i386.deb Size/MD5 checksum: 93628 6dd15a1fb32a3792811a7955083d835e ia64 architecture (Intel ia64) http://security.debian.org/pool/updates/main/libo/libopenssl-ruby/libopenssl-ruby1.6_0.1.4a-1sarge1_ia64.deb Size/MD5 checksum: 112496 8dd845a285ba4c46aa148d5e03e142cd m68k architecture (Motorola Mc680x0) http://security.debian.org/pool/updates/main/libo/libopenssl-ruby/libopenssl-ruby1.6_0.1.4a-1sarge1_m68k.deb Size/MD5 checksum: 94740 25df2cf97eb03a8f1a53c447cfdc7e73 mips architecture (MIPS (Big Endian)) http://security.debian.org/pool/updates/main/libo/libopenssl-ruby/libopenssl-ruby1.6_0.1.4a-1sarge1_mips.deb Size/MD5 checksum: 83622 0637caea582cefd6994e9c1bfd105464 mipsel architecture (MIPS (Little Endian)) http://security.debian.org/pool/updates/main/libo/libopenssl-ruby/libopenssl-ruby1.6_0.1.4a-1sarge1_mipsel.deb Size/MD5 checksum: 82978 a717ab31fb14a34d75c7209ba3ad0bda powerpc architecture (PowerPC) http://security.debian.org/pool/updates/main/libo/libopenssl-ruby/libopenssl-ruby1.6_0.1.4a-1sarge1_powerpc.deb Size/MD5 checksum: 91528 317a63aba89b5255f4bb8f2a3031d563 s390 architecture (IBM S/390) http://security.debian.org/pool/updates/main/libo/libopenssl-ruby/libopenssl-ruby1.6_0.1.4a-1sarge1_s390.deb Size/MD5 checksum: 99954 578551946138e9b1cf38ff65dea29b53 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main Mailing list: debian-security-announce@lists.debian.org Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFHSA5XXm3vHE4uyloRAodSAKDZpGyz7MOQgIJDQ6xCRgSfub/CbwCcCN6G w6EeEIDuMMlhuaQFtNFrI9Q= =wKz0 -----END PGP SIGNATURE----- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] [SECURITY] [DSA 1412-1] New ruby1.9 packages fix insecure SSL certificate validation, Moritz Muehlenhoff |
|---|---|
| Next by Date: | Re: [Full-disclosure] Aurigma ImageUploader 4.1 Multiple stack overflows, Elazar Broad |
| Previous by Thread: | [Full-disclosure] [SECURITY] [DSA 1412-1] New ruby1.9 packages fix insecure SSL certificate validation, Moritz Muehlenhoff |
| Next by Thread: | Re: [Full-disclosure] Aurigma ImageUploader 4.1 Multiple stack overflows, Elazar Broad |
| Indexes: | [Date] [Thread] [Top] [All Lists] |