First published: Fri Nov 22 2013(Updated: )
Kingsoft KDrive Personal before 1.21.0.1880 on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Kingsoft Kdrive | <=1.21.0.1878 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5999 has been assigned a medium severity level due to its potential for man-in-the-middle attacks.
To fix CVE-2013-5999, upgrade Kingsoft KDrive Personal to version 1.21.0.1880 or later.
CVE-2013-5999 is a security vulnerability related to improper validation of SSL certificates.
The potential impact of CVE-2013-5999 includes data interception and unauthorized access to sensitive information.
Users of Kingsoft KDrive Personal version 1.21.0.1878 or earlier on Windows are affected by CVE-2013-5999.