Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-3323

EPSS 1.23% · P79
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-3323

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
setup.exe before 2.573.2.3 in Cygwin does not properly verify the authenticity of packages, which allows remote Cygwin mirror servers or man-in-the-middle attackers to execute arbitrary code via a package list containing the MD5 checksum of a Trojan horse package.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cygwin setup.exe安装及升级过程数据验证漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cygwin是许多自由软件的集合,用于在各种版本的Microsoft Windows上运行UNIX类系统。 Cygwin的Tarball软件包是通过setup.exe安装和升级的,该程序通过明文HTTP或FTP从镜像下载软件包列表和软件包,软件包列表中包含有用于验证完整性的MD5校验和。如果恶意的服务器响应了负责升级软件包的HTTP请求并返回修改的MD5字符串的话,setup.exe就会下载并安装恶意软件包。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-3323

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-3323

登录查看更多情报信息。

Same Patch Batch · n/a · 2008-07-28 · 22 CVEs total

CVE-2008-3355Camera Life 'sitemap.xml.php' SQL注入漏洞
CVE-2008-3348MyioSoft EasyDynamicPages 'index.php' 跨站脚本漏洞
CVE-2008-3347MyioSoft EasyDynamicPages 'index.php'SQL注入漏洞
CVE-2008-3346E-topbiz Shopcart DX 'product_detail.php' SQL注入漏洞
CVE-2008-3345EasyE-Cards多个SQL注入及跨站脚本漏洞
CVE-2008-3344EasyE-Cards多个SQL注入及跨站脚本漏洞
CVE-2008-3343MyioSoft EasyDynamicPages 'index.php'SQL注入漏洞
CVE-2008-3342MyioSoft EasyDynamicPages 'index.php'跨站脚本漏洞
CVE-2008-3341Jobbex JobSite 'search_result' SQL注入漏洞
CVE-2008-3340Jobbex JobSite 'search_result'跨站脚本漏洞
CVE-2008-3339Jobbex JobSite 'search_result.cfm'信息泄露漏洞
CVE-2007-5400RealNetworks RealPlayer SWF文件处理堆溢出漏洞
CVE-2008-3354RunCMS Newbb Plus module 文件包含漏洞
CVE-2008-3353Pure Software Lore 多个跨站脚本攻击漏洞
CVE-2008-3352Nersoft Live_music_plus SQL注入漏洞
CVE-2008-3351Atomphotblog 'atomPhotoBlog.php' SQL注入漏洞
CVE-2008-3350Dnsmasq DCHP Lease 多个远程拒绝服务漏洞
CVE-2008-3349NetApp DATA ONTAP 拒绝服务漏洞
CVE-2008-3066RealPlayer rjbdll.dll ActiveX控件Import方式栈溢出漏洞
CVE-2008-3064RealPlayer未明本地资源参照漏洞

Showing top 20 of 22 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-3323

No comments yet


Leave a comment