CVE-2016-11086

NameCVE-2016-11086
Descriptionlib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs970932

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ruby-oauth (PTS)jessie0.4.7-2vulnerable
stretch0.4.7-3vulnerable
buster0.5.4-1vulnerable
sid, trixie, bullseye, bookworm0.5.4-1.1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ruby-oauthsourceexperimental0.5.6-1
ruby-oauthsourcejessie(unfixed)end-of-life
ruby-oauthsource(unstable)(unfixed)unimportant970932

Notes

https://github.com/oauth-xx/oauth-ruby/issues/137
Likely minor issue since the package that exist is generated by ca-certificates
package and ca-certificates in the package dependency list. Hence even though the
package is vulnerable the problem do not exist in Debian unless the admin has
explicitly removed the file from the filesystem.
Fixing this vulnerability can cause a regression in the case the
admin has intentionally removed this file to not check certificates.

Search for package or bug name: Reporting problems