First published: Thu Jul 18 2013(Updated: )
The Yahoo! Tumblr app before 3.4.1 for iOS sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Tumblr | <=3.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4873 is classified as a medium severity vulnerability due to the risk of credentials being exposed over the network.
To fix CVE-2013-4873, update the Yahoo! Tumblr app to version 3.4.1 or later on iOS devices.
CVE-2013-4873 compromises sensitive user credentials transmitted in cleartext.
Cleartext transmission in CVE-2013-4873 allows attackers to intercept and read sensitive user information easily.
CVE-2013-4873 affects all versions of the Yahoo! Tumblr app for iOS prior to version 3.4.1.