{"schema_version":"1.7.3","id":"GHSA-mmrq-6999-72v8","published":"2022-05-13T01:50:20Z","modified":"2024-12-03T06:08:23.917433Z","aliases":["CVE-2018-16395"],"summary":"Ruby Openssl Allows Incorrect Value Comparison","details":"An issue was discovered in the OpenSSL library in Ruby when two `OpenSSL::X509::Name` objects are compared using `==`, depending on the ordering, non-equal objects may return true. When the first argument is one character longer than the second, or the second argument contains a character that is one less than a character in the same position of the first argument, the result of `==` will be true. This could be leveraged to create an illegitimate certificate that may be accepted as legitimate and then used in signing or encryption operations.","affected":[{"package":{"name":"openssl","ecosystem":"RubyGems","purl":"pkg:gem/openssl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.9"}]}],"versions":["2.0.0","2.0.0.beta.1","2.0.0.beta.2","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mmrq-6999-72v8/GHSA-mmrq-6999-72v8.json"}},{"package":{"name":"openssl","ecosystem":"RubyGems","purl":"pkg:gem/openssl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.1.2"}]}],"versions":["2.1.0","2.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mmrq-6999-72v8/GHSA-mmrq-6999-72v8.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-16395"},{"type":"WEB","url":"https://github.com/ruby/openssl/commit/f653cfa43f0f20e8c440122ea982382b6228e7f5"},{"type":"WEB","url":"https://hackerone.com/reports/387250"},{"type":"WEB","url":"https://www.ruby-lang.org/en/news/2018/11/06/ruby-2-6-0-preview3-released"},{"type":"WEB","url":"https://www.ruby-lang.org/en/news/2018/10/17/ruby-2-5-2-released"},{"type":"WEB","url":"https://www.ruby-lang.org/en/news/2018/10/17/ruby-2-4-5-released"},{"type":"WEB","url":"https://www.ruby-lang.org/en/news/2018/10/17/ruby-2-3-8-released"},{"type":"WEB","url":"https://www.ruby-lang.org/en/news/2018/10/17/openssl-x509-name-equality-check-does-not-work-correctly-cve-2018-16395"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2020.html"},{"type":"WEB","url":"https://www.debian.org/security/2018/dsa-4332"},{"type":"WEB","url":"https://web.archive.org/web/20211206015239/https://securitytracker.com/id/1042105"},{"type":"WEB","url":"https://usn.ubuntu.com/3808-1"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20190221-0002"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2018/10/msg00020.html"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/openssl/CVE-2018-16395.yml"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:2565"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:1948"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:3738"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:3731"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:3730"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:3729"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html"}],"database_specific":{"cwe_ids":[],"github_reviewed":true,"github_reviewed_at":"2023-06-09T22:57:50Z","nvd_published_at":"2018-11-16T18:29:00Z","severity":"CRITICAL"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}