Debian LTS: DLA-1956-1: ruby-openid security update

ruby-openid performed discovery first, and then verification. This allowed an attacker to change the URL used for discovery and trick the server into connecting to the URL. This server in turn could be a private server not publicly accessible. Continue Reading — Debian LTS: DLA-1956-1:...


