First published: Sun Oct 19 2014(Updated: )
The Youth Incorporated (aka com.magzter.youthincorporated) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Magzter Youth Incorporated | =3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7423 is classified as a high severity vulnerability due to its potential for man-in-the-middle attacks.
CVE-2014-7423 allows attackers to spoof SSL servers and obtain sensitive information, making it highly dangerous for users.
To mitigate CVE-2014-7423, users should avoid using the affected version of the Youth Incorporated app and ensure that they use apps that properly verify X.509 certificates.
CVE-2014-7423 affects version 3.0 of the Youth Incorporated application for Android.
As of the discovery of CVE-2014-7423, no patch was provided, so users are advised to uninstall the application until a fix is released.