Back to search
CVE-2008-3249
Published: Jul 21, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
30379
third-party-advisory
x_refsource_SECUNIA
29366
vdb-entry
x_refsource_BID
20080525 SECOBJADV-2008-01: Lenovo SystemUpdate SSL Certificate Issuer Spoofing Vulnerability
mailing-list
x_refsource_BUGTRAQ
ibm-thinkvantage-ssl-spoofing(42638)
vdb-entry
x_refsource_XF
1020112
vdb-entry
x_refsource_SECTRACK
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now