CVE-2014-7749: Medium severity intsig camdictionary vulnerability
The CamDictionary (aka com.intsig.camdict) application 2.3.0.20131118 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7749?
CVE-2014-7749 has been classified with a medium severity due to its potential for allowing man-in-the-middle attacks.
How does CVE-2014-7749 affect users of the CamDictionary application?
CVE-2014-7749 affects users by not verifying X.509 certificates, which can expose sensitive information to attackers.
What are the consequences of not patching CVE-2014-7749?
Not patching CVE-2014-7749 may lead to compromised security, enabling attackers to spoof servers and intercept sensitive data.
How do I fix CVE-2014-7749?
To fix CVE-2014-7749, users should update the CamDictionary application to a version that properly validates SSL certificates.
Is CVE-2014-7749 relevant to all versions of CamDictionary?
CVE-2014-7749 specifically affects version 2.3.0.20131118 of the CamDictionary application on Android.