LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
References
Link | Resource |
---|---|
https://jvn.jp/en/jp/JVN75453852/index.html | Third Party Advisory VDB Entry |
https://linecorp.com/en/security/article/136 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: jpcert
Published: 2018-02-23T15:00:00
Updated: 2018-02-23T14:57:01
Reserved: 2017-11-27T00:00:00
Link: CVE-2018-0518
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-02-23T15:29:00.213
Modified: 2018-03-20T19:16:05.380
Link: CVE-2018-0518
JSON object: View
Redhat Information
No data.
CWE