CVE-2014-0036 Information

Description

The rbovirt gem before 0.0.24 for Ruby uses the rest-client gem with SSL verification disabled which allows remote attackers to conduct man-in-the-middle attacks via unspecified vectors.

Reference

http://lists.fedoraproject.org/pipermail/package-announce/2014-March/130148.html http://lists.fedoraproject.org/pipermail/package-announce/2014-March/130180.html http://seclists.org/oss-sec/2014/q1/509 https://bugzilla.redhat.com/show_bug.cgi?id=1058595

Share on: