Open Handset Alliance Android SSL Certificate Spoofing Vulnerability
BID:48940
Info
Open Handset Alliance Android SSL Certificate Spoofing Vulnerability
| Bugtraq ID: | 48940 |
| Class: | Design Error |
| CVE: |
CVE-2010-4832 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 29 2011 12:00AM |
| Updated: | Jul 22 2014 12:07AM |
| Credit: | Shuhei Ohtani of Business information govern CO., LTD |
| Vulnerable: |
Open Handset Alliance Android 2.0.1 Open Handset Alliance Android 2.1 Open Handset Alliance Android 1.5 Open Handset Alliance Android 1.0 Open Handset Alliance Android 0 |
| Not Vulnerable: |
Open Handset Alliance Android 2.2 |
Discussion
Open Handset Alliance Android SSL Certificate Spoofing Vulnerability
Open Handset Alliance Android is prone to a security vulnerability that may allow attackers to spoof SSL certificates.
Attackers can exploit this issue to display incorrect SSL certificates. Successful exploits will cause victims to assume that they are viewing a legitimate site.
Open Handset Alliance Android is prone to a security vulnerability that may allow attackers to spoof SSL certificates.
Attackers can exploit this issue to display incorrect SSL certificates. Successful exploits will cause victims to assume that they are viewing a legitimate site.
Exploit / POC
Open Handset Alliance Android SSL Certificate Spoofing Vulnerability
Exploit code is available. Please see the references for more information.
Exploit code is available. Please see the references for more information.
Solution / Fix
Open Handset Alliance Android SSL Certificate Spoofing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Open Handset Alliance Android SSL Certificate Spoofing Vulnerability
References:
References:
- Android Homepage (Open Handset Alliance)
- Evading Scanning via the Android Event Model (Privateer Labs)