CVE-2018-0518: Medium severity line vulnerability
Published Feb 23, 2018
·Updated
LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
1 affected component
linecorp Line Iphone Os>=7.1.3<=7.15
Event History
Feb 23, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-0518.
2
What is the severity of CVE-2018-0518?
The severity of CVE-2018-0518 is medium with a CVSS score of 5.9.
3
What is the affected software for CVE-2018-0518?
The affected software for CVE-2018-0518 is LINE for iOS versions 7.1.3 to 7.1.5.
4
What is the impact of CVE-2018-0518?
CVE-2018-0518 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
5
How can I fix CVE-2018-0518?
To fix CVE-2018-0518, update LINE for iOS to a version higher than 7.1.5.