CVE-2014-3908: Medium severity amazon kindle vulnerability
The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3908?
CVE-2014-3908 is classified as a medium severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2014-3908?
To fix CVE-2014-3908, update the Amazon Kindle application to version 4.5.0 or later for Android.
What types of attacks can CVE-2014-3908 allow?
CVE-2014-3908 can allow man-in-the-middle attackers to spoof SSL servers and intercept sensitive information.
Which versions of the Amazon Kindle app are affected by CVE-2014-3908?
CVE-2014-3908 affects the Amazon Kindle application versions prior to 4.5.0 for Android, including 4.4.4 and 4.4.0.
What does CVE-2014-3908 exploit in the Amazon Kindle application?
CVE-2014-3908 exploits the lack of verification for X.509 certificates from SSL servers in the affected versions of the Kindle app.