First published: Sat Jun 03 2017(Updated: )
In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certificate.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Lenovo Service Bridge |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8231 is rated as a medium severity vulnerability.
To fix CVE-2016-8231, upgrade to Lenovo Service Bridge version 4 or later.
CVE-2016-8231 allows an attacker to exploit the vulnerability to insert a forged code signing certificate.
Lenovo Service Bridge versions prior to 4 are affected by CVE-2016-8231.
There are no official workarounds for CVE-2016-8231; updating is recommended.