CVE-2018-8955

The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remote attackers to execute arbitrary code by changing the filename while leaving the file's digital signature unchanged.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:bitdefender:gravityzone:-:*:*:*:*:*:*:*

Information

Published : 2018-10-24 15:29

Updated : 2019-01-25 12:01


NVD link : CVE-2018-8955

Mitre link : CVE-2018-8955


JSON object : View

CWE
CWE-347

Improper Verification of Cryptographic Signature

Advertisement

dedicated server usa

Products Affected

bitdefender

  • gravityzone