Уязвимость CVE-2018-16395: Информация

Описание

An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When two OpenSSL::X509::Name objects are compared using ==, depending on the ordering, non-equal objects may return true. When the first argument is one character longer than the second, or the second argument contains a character that is one less than a character in the same position of the first argument, the result of == will be true. This could be leveraged to create an illegitimate certificate that may be accepted as legitimate and then used in signing or encryption operations.

Важность: CRITICAL (9,8) Вектор: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Опубликовано: 16 ноября 2018 г.
Изменено: 3 октября 2019 г.

Исправленные пакеты

Имя пакета
Ветка
Исправлено в версии
Версия в репозитории
Errata ID
№ Задания
Состояние
rubysisyphus2.5.4-alt13.1.4-alt4.4ALT-PU-2019-1050-1219345Исправлено
rubyp102.5.4-alt13.1.4-alt2.p10.1ALT-PU-2019-1050-1219345Исправлено
rubyp92.5.4-alt12.5.9-alt1ALT-PU-2019-1050-1219345Исправлено
rubyc10f12.5.4-alt12.7.4-alt2.2.1ALT-PU-2019-1050-1219345Исправлено
rubyc9f22.5.4-alt12.7.6-alt0.1.c9f2ALT-PU-2019-1050-1219345Исправлено

Ссылки на рекомендации, решения и инструменты

    1. Конфигурация 1

      cpe:2.3:a:ruby-lang:ruby:2.6.0:preview1:*:*:*:*:*:*

      cpe:2.3:a:ruby-lang:ruby:2.6.0:preview2:*:*:*:*:*:*

      cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*
      Start including
      2.3.0
      End including
      2.3.7

      cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*
      Start including
      2.4.0
      End including
      2.4.4

      cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*
      Start including
      2.5.0
      End including
      2.5.1

      cpe:2.3:a:ruby-lang:openssl:*:*:*:*:*:ruby:*:*
      End excliding
      2.1.2

      Конфигурация 2

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

      Конфигурация 3

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      Конфигурация 4

      cpe:2.3:o:redhat:enterprise_linux:7.4:*:*:*:*:*:*:*