Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Lenovo System Update SSL Certificate Validation Security Bypass Vulnerability

Lenovo System Update is prone to a security-bypass vulnerability because the application fails to properly check SSL certificates.

Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks by impersonating trusted servers, which can lead to the installation of arbitrary software on an affected computer. This may result in a complete compromise of the computer.

This issue affects Lenovo System Update 3 (Version 3.13.0005, Build date 2008-1-3); other versions may also be vulnerable.







 

Privacy Statement
Copyright 2008, SecurityFocus