Lenovo System Update SSL Certificate Validation Security Bypass Vulnerability
BID:29366
Info
Lenovo System Update SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 29366 |
| Class: | Design Error |
| CVE: |
CVE-2008-3249 |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | Security Objectives |
| Vulnerable: |
Lenovo System Update 3 |
| Not Vulnerable: |
Lenovo System Update 3.14 |
Discussion
Lenovo System Update SSL Certificate Validation Security Bypass Vulnerability
Lenovo System Update is prone to a security-bypass vulnerability because the application fails to properly check SSL certificates.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks by impersonating trusted servers, which can lead to the installation of arbitrary software on an affected computer. This may result in a complete compromise of the computer.
This issue affects Lenovo System Update 3 (Version 3.13.0005, Build date 2008-1-3); other versions may also be vulnerable.
Lenovo System Update is prone to a security-bypass vulnerability because the application fails to properly check SSL certificates.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks by impersonating trusted servers, which can lead to the installation of arbitrary software on an affected computer. This may result in a complete compromise of the computer.
This issue affects Lenovo System Update 3 (Version 3.13.0005, Build date 2008-1-3); other versions may also be vulnerable.
Exploit / POC
Lenovo System Update SSL Certificate Validation Security Bypass Vulnerability
Attackers can use standard tools to exploit this issue.
Attackers can use standard tools to exploit this issue.
Solution / Fix
Lenovo System Update SSL Certificate Validation Security Bypass Vulnerability
Solution:
This issue is reported to be fixed in Lenovo System Update 3.14; Symantec has not been able to verify this information.
Solution:
This issue is reported to be fixed in Lenovo System Update 3.14; Symantec has not been able to verify this information.
References
Lenovo System Update SSL Certificate Validation Security Bypass Vulnerability
References:
References:
- System Update (Lenovo)
- SECOBJADV-2008-01: Lenovo SystemUpdate SSL Certificate Issuer Spoofing Vulnerabi ("Security Objectives, Inc."
) - SECOBJADV-2008-01 Lenovo SystemUpdate SSL Certificate Issuer Spoofing Vulnerabil (Security Objectives)