Vulnerability CVE-2008-3323


Published: 2008-07-28   Modified: 2012-02-12

Description:
setup.exe before 2.573.2.3 in Cygwin does not properly verify the authenticity of packages, which allows remote Cygwin mirror servers or man-in-the-middle attackers to execute arbitrary code via a package list containing the MD5 checksum of a Trojan horse package.

See advisories in our WLB2 database:
Topic
Author
Date
High
Cygwin Installation and Update Process can be Subverted Vulnerability
advisories host ...
31.07.2008

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:N/AC:H/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.6/10
10/10
4.9/10
Exploit range
Attack complexity
Authentication
Remote
High
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Redhat -> Cygwin 

 References:
http://cygwin.com/ml/cygwin-announce/2008-08/msg00001.html
http://securityreason.com/securityalert/4051
http://www.security-objectives.com/advisories/SECOBJADV-2008-02.txt
http://www.securityfocus.com/archive/1/494756/100/0/threaded
http://www.securityfocus.com/bid/30375
http://www.vupen.com/english/advisories/2008/2321
https://bugzilla.redhat.com/show_bug.cgi?id=449929
https://exchange.xforce.ibmcloud.com/vulnerabilities/44047

Copyright 2024, cxsecurity.com

 

Back to Top