CVE-2014-5808: Medium severity whisper vulnerability
The Whisper (aka sh.whisper) application 4.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5808?
CVE-2014-5808 is classified as a medium severity vulnerability due to its potential for man-in-the-middle attacks.
How does CVE-2014-5808 exploit the Whisper application?
CVE-2014-5808 allows attackers to spoof SSL servers by exploiting the application's failure to verify X.509 certificates.
What are the potential consequences of CVE-2014-5808?
Exploitation of CVE-2014-5808 can result in unauthorized access to sensitive user information.
Is CVE-2014-5808 present in versions other than 4.0.6 of the Whisper application?
No, CVE-2014-5808 specifically affects version 4.0.6 of the Whisper application on Android.
How can users protect themselves from CVE-2014-5808?
Users can mitigate the risk of CVE-2014-5808 by updating to a secure version of the Whisper application that verifies X.509 certificates.