CVE-2014-5727: Medium severity utorrent remote vulnerability
The uTorrent Remote (aka com.utorrent.web) application 1.0.20110929 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5727?
CVE-2014-5727 is considered a high severity vulnerability due to the potential for man-in-the-middle attacks.
How does CVE-2014-5727 affect uTorrent Remote?
CVE-2014-5727 allows attackers to spoof SSL servers by exploiting the lack of certificate verification in uTorrent Remote.
What information can be compromised due to CVE-2014-5727?
Sensitive information transmitted over the network can be intercepted by attackers due to the vulnerability in CVE-2014-5727.
How do I fix CVE-2014-5727?
To mitigate CVE-2014-5727, update the uTorrent Remote application to a version that properly verifies X.509 certificates.
Is CVE-2014-5727 fixed in later versions of uTorrent?
Yes, later versions of uTorrent Remote include fixes for the certificate verification issue exploited by CVE-2014-5727.