First published: Tue Oct 31 2023(Updated: )
LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM (man-in-the-middle) attacker.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
LINE | =1.0.0 | |
LINE | =1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2968 is a vulnerability in LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 that allows for MITM (man-in-the-middle) attacks due to non-SSL/TLS communications.
CVE-2015-2968 allows a MITM attacker to inject a script and invoke any API on the application.
The severity of CVE-2015-2968 is medium with a CVSS score of 5.9.
CVE-2015-2968 is associated with CWE-924: Improper Restriction of Operations within the Bounds of a Memory Buffer.
To fix CVE-2015-2968, update LINE@ for Android and iOS to a version that supports SSL/TLS communications.