Ubuntu Security Update USN-8431-1: Ruby vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
6,166
Reaction score
88
Credits
-1,257
It was discovered that Ruby's Net::IMAP library did not properly verify that Transport Layer Security (TLS) encryption was started after issuing a STARTTLS command. A remote attacker could possibly use this issue to perform a machine-in-the-middle attack and silently bypass TLS encryption. (CVE-2026-42246) It was also discovered that Ruby's Net::IMAP library did not validate string arguments passed to certain commands. A remote attacker could possibly use this issue to inject arbitrary IMAP commands. (CVE-2026-42257)

Continue reading...
 


Follow Linux.org

Members online


Top