PT-2008-4839 · Don Ho · Notepad++

Publicado

2008-08-01

·

Atualizado

2008-09-05

·

CVE-2008-3436

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Notepad++ versions prior to 4.8.1
Description The issue concerns the GUP generic update process, which does not properly verify the authenticity of updates. This allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update. Techniques such as evilgrade and DNS cache poisoning can be used to exploit this issue.
Recommendations For versions prior to 4.8.1, update to version 4.8.1 or later to resolve the issue.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3436

Produtos afetados

Notepad++