PT-2008-4838 · Linkedin · Linkedin Browser Toolbar

Publicado

2008-08-01

·

Atualizado

2008-09-05

·

CVE-2008-3435

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions LinkedIn Browser Toolbar versions 3.0.3.1100 and earlier
Description The issue allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update. This can be achieved through techniques such as evilgrade and DNS cache poisoning, which exploit the lack of proper verification of update authenticity.
Recommendations For versions 3.0.3.1100 and earlier, update to a version that properly verifies the authenticity of updates to prevent man-in-the-middle attacks.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3435

Produtos afetados

Linkedin Browser Toolbar