CVE Database
/

CVE-2008-3249

Back to search

CVE-2008-3249

Published: Jul 21, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.

VendorProductVersions

n/a

n/a

affected
n/a

References

30379
third-party-advisory
x_refsource_SECUNIA
29366
vdb-entry
x_refsource_BID
1020112
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now