CVE-2015-2968
LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM (man-in-the-middle) attacker.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-2968?
CVE-2015-2968 is a vulnerability in LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 that allows for MITM (man-in-the-middle) attacks due to non-SSL/TLS communications.
How does CVE-2015-2968 affect LINE@ for Android and iOS?
CVE-2015-2968 allows a MITM attacker to inject a script and invoke any API on the application.
What is the severity of CVE-2015-2968?
The severity of CVE-2015-2968 is medium with a CVSS score of 5.9.
What is the Common Weakness Enumeration (CWE) for CVE-2015-2968?
CVE-2015-2968 is associated with CWE-924: Improper Restriction of Operations within the Bounds of a Memory Buffer.
How can I fix CVE-2015-2968?
To fix CVE-2015-2968, update LINE@ for Android and iOS to a version that supports SSL/TLS communications.