CVE-2008-3249: Medium severity lenovo system update vulnerability
The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3249?
CVE-2008-3249 is considered a high-severity vulnerability due to the potential for arbitrary package installation by remote attackers.
How do I fix CVE-2008-3249?
To fix CVE-2008-3249, update Lenovo System Update to version 3.14 or later, which properly validates SSL certificates.
What systems are affected by CVE-2008-3249?
CVE-2008-3249 affects Lenovo System Update versions up to and including 3.13.
What type of attacks can exploit CVE-2008-3249?
CVE-2008-3249 can be exploited through man-in-the-middle attacks where an attacker installs arbitrary packages using a forged SSL certificate.
Is there a risk of data compromise with CVE-2008-3249?
Yes, CVE-2008-3249 poses a risk of data compromise since it allows remote attackers to gain control over the system by installing malicious software.