First published: Wed Aug 21 2013(Updated: )
The Yahoo! Japan Yafuoku! application 4.3.0 and earlier for iOS and Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Yafuoku\! | <=4.3.0 | |
Yahoo Yafuoku\! | <=4.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4699 has a high severity rating due to the potential for man-in-the-middle attacks that can compromise sensitive information.
To fix CVE-2013-4699, update the Yahoo! Japan Yafuoku! application to version 4.4.0 or later, which includes proper SSL certificate validation.
CVE-2013-4699 affects the Yahoo! Japan Yafuoku! application on both iOS and Android devices with versions up to 4.3.0.
The risk associated with CVE-2013-4699 is that attackers can spoof SSL servers, leading to unauthorized access to sensitive user data.
No, CVE-2013-4699 is no longer a threat in versions 4.4.0 and above of the Yahoo! Japan Yafuoku! application, where the vulnerability has been addressed.