PT-2014-4424 · Justsystems · Just Online Update+1
Publicado
2014-06-16
·
Atualizado
2014-06-16
·
CVE-2014-2003
CVSS v2.0
7.6
Alta
| Vetor | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
JustSystems JUST Online Update versions prior to the version that includes the fix for this issue
Description
The issue is related to the improper validation of signatures of update modules, which allows remote attackers to spoof modules and execute arbitrary code via a crafted signature. This affects products such as Ichitaro through 2014.
Recommendations
For JustSystems JUST Online Update, update to a version that properly validates signatures of update modules to prevent remote attackers from spoofing modules and executing arbitrary code.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ichitaro
Just Online Update