PT-2008-4838 · Linkedin · Linkedin Browser Toolbar

Published

2008-08-01

·

Updated

2008-09-05

·

CVE-2008-3435

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions LinkedIn Browser Toolbar versions 3.0.3.1100 and earlier
Description The issue allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update. This can be achieved through techniques such as evilgrade and DNS cache poisoning, which exploit the lack of proper verification of update authenticity.
Recommendations For versions 3.0.3.1100 and earlier, update to a version that properly verifies the authenticity of updates to prevent man-in-the-middle attacks.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3435

Affected Products

Linkedin Browser Toolbar