First published: Sat Aug 16 2014(Updated: )
LINE 3.2.1.83 and earlier on Windows and 3.2.1 and earlier on OS X does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
LINE | <=3.2.1.83 | |
Microsoft Windows | ||
LINE | <=3.2.1 | |
Apple iOS and macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7144 is classified as a high severity vulnerability due to its potential for man-in-the-middle attacks.
To fix CVE-2013-7144, upgrade to LINE version 3.2.1.84 or later on Windows and 3.2.2 or later on OS X.
Exploiting CVE-2013-7144 can allow attackers to spoof servers and intercept sensitive information transmitted over SSL.
LINE versions 3.2.1.83 and earlier on Windows and 3.2.1 and earlier on OS X are affected by CVE-2013-7144.
No, CVE-2013-7144 specifically affects certain versions of LINE on Windows and Mac OS X, but not newer versions of these operating systems.