Title : Cygwin "setup.exe" Packages Verification Security Weakness VUPEN ID : VUPEN/ADV-2008-2321 CVE ID : CVE-2008-3323 CWE ID : CWE-345
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-11
Technical Description
A weakness has been identified in Cygwin, which could be exploited by attackers to bypass security restrictions. This issue is caused by an error in the "setup.exe" utility that does not properly verify the integrity of downloaded package list and packages, which could be exploited by attackers to compromise a vulnerable system by tricking a user into downloading a package from a malicious or compromised mirror.