CVE-2008-3435: Code Injection
LinkedIn Browser Toolbar 3.0.3.1100 and earlier does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3435?
CVE-2008-3435 is considered a critical vulnerability due to the potential for man-in-the-middle attacks and arbitrary code execution.
How do I fix CVE-2008-3435?
To fix CVE-2008-3435, users should upgrade to a later version of the LinkedIn Browser Toolbar that properly verifies the authenticity of updates.
What systems are affected by CVE-2008-3435?
CVE-2008-3435 affects LinkedIn Browser Toolbar versions 3.0.3.1100 and earlier.
Can CVE-2008-3435 be exploited remotely?
Yes, CVE-2008-3435 can be exploited remotely by attackers using techniques like DNS cache poisoning.
What types of attacks are associated with CVE-2008-3435?
CVE-2008-3435 is associated with man-in-the-middle attacks, allowing attackers to execute arbitrary code via a Trojan horse update.