Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7rhp-mjch-qq88

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.

Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.

EPSS

Процентиль: 89%
0.04578
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 9.8
nvd
почти 24 года назад

Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.

EPSS

Процентиль: 89%
0.04578
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-494