SSL Certificate Verification Flaw in Foxit MobilePDF for Android
CVE-2014-6853

Currently unrated

Key Information:

Vendor
Foxit
Vendor
CVE Published:
1 October 2014

Summary

The Foxit MobilePDF application for Android, version 2.2.0.0616, presents a vulnerability by failing to correctly validate X.509 certificates from SSL servers. This oversight permits man-in-the-middle attackers to execute spoofing attacks, thereby gaining access to sensitive information that is meant to be securely transmitted. Users of the affected application are at risk, as the lack of proper certificate verification allows harmful actors to impersonate legitimate servers using crafted certificates.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.