Описание
Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.
Ссылки
- Broken Link
- Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
- Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
- Third Party AdvisoryVDB Entry
- Broken Link
- Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
- Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 1.6 (исключая)
cpe:2.3:a:symantec:liveupdate:*:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04578
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-494
CWE-494
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.
EPSS
Процентиль: 89%
0.04578
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-494
CWE-494