Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.
{
"binaries": [
{
"binary_version": "2.3.1-2~ubuntu16.04.16+esm14",
"binary_name": "libruby2.3"
},
{
"binary_version": "2.3.1-2~ubuntu16.04.16+esm14",
"binary_name": "ruby2.3"
},
{
"binary_version": "2.3.1-2~ubuntu16.04.16+esm14",
"binary_name": "ruby2.3-tcltk"
}
],
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"
}