CVE-2013-5999: Medium severity kingsoft kdrive vulnerability
Published Nov 22, 2013
·Updated
Kingsoft KDrive Personal before 1.21.0.1880 on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
1 affected component
Kingsoft Kdrive Windows<=1.21.0.1878
Event History
Nov 22, 2013
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5999?
CVE-2013-5999 has been assigned a medium severity level due to its potential for man-in-the-middle attacks.
2
How do I fix CVE-2013-5999?
To fix CVE-2013-5999, upgrade Kingsoft KDrive Personal to version 1.21.0.1880 or later.
3
What type of vulnerability is CVE-2013-5999?
CVE-2013-5999 is a security vulnerability related to improper validation of SSL certificates.
4
What are the potential impacts of CVE-2013-5999?
The potential impact of CVE-2013-5999 includes data interception and unauthorized access to sensitive information.
5
Who is affected by CVE-2013-5999?
Users of Kingsoft KDrive Personal version 1.21.0.1878 or earlier on Windows are affected by CVE-2013-5999.