The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2008-07-21T17:00:00
Updated: 2017-08-07T12:57:01
Reserved: 2008-07-21T00:00:00
Link: CVE-2008-3249
JSON object: View
NVD Information
Status : Modified
Published: 2008-07-21T17:41:00.000
Modified: 2017-08-08T01:31:42.747
Link: CVE-2008-3249
JSON object: View
Redhat Information
No data.
CWE