CVE-2014-5976: Medium severity alibaba vulnerability
Published Sep 20, 2014
·Updated
The alibaba (aka com.alibaba.wireless) application 4.1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
1 affected component
Alibaba Alibaba Android=4.1.0.0
Event History
Sep 20, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5976?
CVE-2014-5976 has a medium severity due to the potential for man-in-the-middle attacks.
2
How do I fix CVE-2014-5976?
To fix CVE-2014-5976, ensure that SSL certificate validation is implemented in the application.
3
What applications are affected by CVE-2014-5976?
CVE-2014-5976 specifically affects the Alibaba application version 4.1.0.0 for Android.
4
What attackers can exploit CVE-2014-5976?
Man-in-the-middle attackers can exploit CVE-2014-5976 by spoofing SSL servers to intercept sensitive information.
5
What information can be compromised due to CVE-2014-5976?
Sensitive user information can be compromised due to the lack of certificate verification in CVE-2014-5976.