Vulnerability Bulletins

DSA-3245 ruby1.8 - security update

   
Affected software Debian
 
It was discovered that the Ruby OpenSSL extension, part of the interpreterfor the Ruby language, did not properly implement hostname matching, inviolation of RFC 6125. This could allow remote attackers to perform aman-in-the-middle attack via crafted SSL certificates.

More info:

https://www.debian.org/security/2015/dsa-3245