CVE-2014-7085: Medium severity independent i newspaper vulnerability
The i Newspaper (aka com.independent.thei) application @7F080184 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7085?
CVE-2014-7085 is considered a high severity vulnerability due to its potential to allow man-in-the-middle attacks.
How does CVE-2014-7085 affect Android applications?
CVE-2014-7085 affects Android applications by not validating X.509 certificates, which can be exploited by attackers to intercept sensitive data.
What are the potential impacts of CVE-2014-7085?
The potential impacts of CVE-2014-7085 include unauthorized access to sensitive information and data breaches due to spoofed SSL servers.
How do I fix CVE-2014-7085?
To fix CVE-2014-7085, ensure that the application implements proper SSL certificate validation for secure connections.
Who is affected by CVE-2014-7085?
Users of the i Newspaper application on Android, specifically version @7F080184, are affected by CVE-2014-7085.