Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-3437

Опубликовано: 01 авг. 2008
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 7.5

Описание

OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

РелизСтатусПримечание
dapper

not-affected

update feature disabled
devel

not-affected

update feature disabled
feisty

not-affected

update feature disabled
gutsy

not-affected

update feature disabled
hardy

not-affected

update feature disabled
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 78%
0.01893
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
около 18 лет назад

OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

debian
около 18 лет назад

OpenOffice.org (OOo) before 2.1.0 does not properly verify the authent ...

github
больше 4 лет назад

OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

EPSS

Процентиль: 78%
0.01893
Низкий

7.5 High

CVSS2