CVE-2014-5998: Medium severity skydrive assistant vulnerability
The SkyDrive Assistant (aka com.dhh.sky) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5998?
CVE-2014-5998 is classified as a high severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2014-5998?
To mitigate CVE-2014-5998, ensure that your application validates X.509 certificates properly and updates to a version that addresses this vulnerability.
What type of attack can exploit CVE-2014-5998?
CVE-2014-5998 can be exploited through man-in-the-middle attacks, where attackers can intercept and manipulate data exchanged between the application and servers.
Which application is affected by CVE-2014-5998?
CVE-2014-5998 affects the SkyDrive Assistant application, specifically version 2.1 for Android.
What information can be compromised by CVE-2014-5998?
CVE-2014-5998 allows attackers to obtain sensitive information of users through the use of maliciously crafted SSL certificates.