Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-3437

Опубликовано: 01 авг. 2008
Источник: ubuntu
Приоритет: low
CVSS2: 7.5

Описание

OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

РелизСтатусПримечание
dapper

not-affected

update feature disabled
devel

not-affected

update feature disabled
feisty

not-affected

update feature disabled
gutsy

not-affected

update feature disabled
hardy

not-affected

update feature disabled
upstream

needs-triage

Показывать по

Ссылки на источники

7.5 High

CVSS2

Связанные уязвимости

nvd
больше 17 лет назад

OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

debian
больше 17 лет назад

OpenOffice.org (OOo) before 2.1.0 does not properly verify the authent ...

github
почти 4 года назад

OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

7.5 High

CVSS2