Yahoo! ybox For Android CVE-2014-5881 SSL Certificate Validation Security Bypass Vulnerability
BID:70148
Info
Yahoo! ybox For Android CVE-2014-5881 SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 70148 |
| Class: | Design Error |
| CVE: |
CVE-2014-5881 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2014 12:00AM |
| Updated: | Sep 11 2014 12:00AM |
| Credit: | Yahoo Japan Corporation |
| Vulnerable: |
Yahoo! Yahoo! ybox 1.5.4 ~~~android~~ Yahoo! Yahoo! ybox 1.5.1 ~~~android~~ |
| Not Vulnerable: | |
Discussion
Yahoo! ybox For Android CVE-2014-5881 SSL Certificate Validation Security Bypass Vulnerability
Yahoo! ybox for Android is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Yahoo! ybox 1.5.4 and prior are vulnerable.
Yahoo! ybox for Android is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Yahoo! ybox 1.5.4 and prior are vulnerable.
Solution / Fix
Yahoo! ybox For Android CVE-2014-5881 SSL Certificate Validation Security Bypass Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.