CVE-2018-13140
Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download installation packages.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
http://packetstormsecurity.com/files/149468/Antidote-9.5.1-Code-Execution.html, http://seclists.org/fulldisclosure/2018/Sep/38, https://sysdream.com/news/lab/2018-09-21-cve-2018-13140-antidote-remote-code-execution-against-the-update-component/, http://seclists.org/fulldisclosure/2018/Sep/38, http://packetstormsecurity.com/files/149468/Antidote-9.5.1-Code-Execution.html, http://seclists.org/fulldisclosure/2018/Sep/38, https://sysdream.com/news/lab/2018-09-21-cve-2018-13140-antidote-remote-code-execution-against-the-update-component/
