CVE-2021-41067
Last modified
CVE-2021-41067 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in Listary through 6. Improper implementation of the update process leads to the download of software updates with a /check-update HTTP-based connection. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
An issue was discovered in Listary through 6. Improper implementation of the update process leads to the download of software updates with a /check-update HTTP-based connection. This can be exploited with MITM techniques. Together with the lack of package validation, it can lead to manipulation of update packages that can cause an installation of malicious content.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Listary | Listary | <= 6 |
References
- https://www.listary.com/downloadVendor Advisory
- https://www.listary.com/downloadVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-41067?
How severe is CVE-2021-41067?
How do I fix CVE-2021-41067?
Are you affected by CVE-2021-41067?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
