CVE-2007-5770 describes a critical vulnerability in several Ruby libraries (Net::ftptls, Net::telnets, Net::imap, Net::pop, and Net::smtp) within Ruby versions 1.8.5 and 1.8.6. These libraries fail to validate the commonName (CN) field in server SSL certificates against the requested domain name, enabling man-in-the-middle attacks or website spoofing. With a CVSS score of 5.0, this vulnerability allows unauthenticated attackers to compromise data integrity (I:P) over the network (AV:N/AC:L), though it does not impact confidentiality or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.5CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:1.8.5:*:*:*:*:*:*:* | ||
1.8.6CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:1.8.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.