CVE-2014-5772

govhk government_bookstore: Sicherheitsluecke

Description

The Government Bookstore (aka hksarg.isd.sop.govbookstore) application 1.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

govhkgovernment_bookstore

Metrics

20.1 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
none
no public PoC known
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2014-09-09 10:00 UTC

References & sources