First published: Tue Sep 09 2014(Updated: )
The Web Browser for Android (aka explore.web.browser) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Web Browser For Android | =1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5770 has a medium severity rating due to its potential to allow man-in-the-middle attacks.
To fix CVE-2014-5770, you should update the Web Browser for Android application to a version that properly verifies SSL certificates.
CVE-2014-5770 can allow man-in-the-middle attackers to spoof servers and intercept sensitive information.
CVE-2014-5770 affects the Web Browser for Android version 1.2.
CVE-2014-5770 reveals that the Web Browser for Android does not verify X.509 certificates from SSL servers.