Vulnerability Description
LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linecorp | Line | >= 7.1.3, <= 7.15 |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN75453852/index.htmlThird Party AdvisoryVDB Entry
- https://linecorp.com/en/security/article/136Vendor Advisory
- https://jvn.jp/en/jp/JVN75453852/index.htmlThird Party AdvisoryVDB Entry
- https://linecorp.com/en/security/article/136Vendor Advisory
FAQ
What is CVE-2018-0518?
CVE-2018-0518 is a vulnerability with a CVSS score of 5.9 (MEDIUM). LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certif...
How severe is CVE-2018-0518?
CVE-2018-0518 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-0518?
Check the references section above for vendor advisories and patch information. Affected products include: Linecorp Line.