Get a Pentest and security assessment of your IT network.

Advisories

SECOBJADV-2008-01.txt

Security Objectives Advisory – Lenovo System Update allows arbitrary update executables to be downloaded and installed from a rogue server. The Client DLL does not perform certificate chain verification when initiating an SSL connection with the server. Version 3.13.0005 Build date 2008-1-3 is affected. Other versions may also be affected.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/66693/SECOBJADV-2008-01.txt

Source: https://packetstormsecurity.com/files/66693/SECOBJADV-2008-01.txt.html

Related posts
Advisories

Secunia Security Advisory 15017

Advisories

Secunia Security Advisory 18394

Advisories

Secunia Security Advisory 21136

Advisories

Secunia Security Advisory 24114