CVE-2014-6980: Medium severity naver line vulnerability
The LINE PLAY (aka jp.naver.lineplay.android) application 2.3.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6980?
CVE-2014-6980 is considered high severity due to the potential for man-in-the-middle attacks that can compromise sensitive information.
How do I fix CVE-2014-6980?
To fix CVE-2014-6980, update the LINE PLAY application to the latest version that addresses this SSL certificate verification issue.
What are the risks associated with CVE-2014-6980?
The risks associated with CVE-2014-6980 include exposure of sensitive data due to unverified X.509 certificates, allowing attackers to impersonate secure servers.
Which version of LINE PLAY is affected by CVE-2014-6980?
LINE PLAY version 2.3.1.1 for Android is the affected version related to CVE-2014-6980.
What is the exploitation mechanism for CVE-2014-6980?
CVE-2014-6980 can be exploited through a crafted SSL certificate that the application does not validate, enabling a man-in-the-middle attack.