Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to easily convince a user to execute arbitrary code
Workaround:
The product does not validate, or incorrectly validates, a certificate.
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/403768 | third party advisory us government resource |
https://github.com/pbatard/rufus/issues/1009 | third party advisory |
http://www.securityfocus.com/bid/100516 | vdb entry third party advisory |
https://github.com/pbatard/rufus/commit/c3c39f7f8a11f612c4ebf7affce25ec6928eb1cb | third party advisory |